designscope

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content and Figma data, creating a potential surface for indirect prompt injection where malicious instructions could be embedded in analyzed materials. * Ingestion points: External data is retrieved via the web_fetch tool and Figma MCP tools, and processed by scripts like scripts/extract_css_vars.py. * Boundary markers: The procedure in SKILL.md does not explicitly instruct the agent to use delimiters or ignore instructions found within the fetched data. * Capability inventory: The skill has access to bash for running scripts and write_to_file for generating design artifacts, which could be misused if an injection is successful. * Sanitization: Extraction scripts use specific regular expressions to filter for CSS variables, providing a degree of structural validation for incoming data.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves HTML and CSS files from user-provided URLs using the web_fetch tool and Python's urllib library. This is a functional requirement for analyzing external design systems.
  • [COMMAND_EXECUTION]: The skill uses the bash tool to execute several local Python scripts included in the repository, such as check_contrast.py and lint_design_md.py, to process and validate design data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — designscope