design-md

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads and executes the @google/design.md utility from npm using npx. This package is maintained by Google, which is a trusted organization.
  • [COMMAND_EXECUTION]: Runs the design.md CLI to perform linting, contrast validation, and token exports.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided design files containing YAML and Markdown. As the skill is capable of file-system writes and command execution based on these specifications, this data ingestion presents an attack surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:01 PM
Security Audit — agent-trust-hub — design-md