claude-design

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow that requires ingesting and processing external data from a user's repository, including brand documents, UI kits, and source code files (e.g., stylesheets and components) to inform the design process.
  • Ingestion points: SKILL.md (Workflow and 'Design Principle' sections) specifies reading repository content such as theme files, token files, and global stylesheets.
  • Boundary markers: The skill does not explicitly define delimiters or boundary markers for the agent to use when processing this external content.
  • Capability inventory: The skill includes the capability to write executable HTML/JS files to the local system and suggests environment-based verification.
  • Sanitization: The skill provides high-level guidance on avoiding unnecessary dependencies but does not prescribe specific sanitization for data extracted from documents.
  • [DYNAMIC_EXECUTION]: A primary function of the skill is the generation of functional HTML, CSS, and JavaScript artifacts. The agent is instructed to write these scripts to disk to create interactive prototypes, decks, and component labs.
  • [COMMAND_EXECUTION]: The skill includes a verification step where the agent is encouraged to run local syntax checks or static analysis tools and to open files in a browser context to check for console errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:01 PM
Security Audit — agent-trust-hub — claude-design