hmos-design-visual-mobile
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill instructions and component templates rely entirely on local repository assets, referencing theme tokens and static resources via relative paths.
- [EXTERNAL_DOWNLOADS]: Documentation and metadata files (e.g., hmsymbol-map.json) contain reference links to official Huawei developer resources on
developer.huawei.com. These are recognized as well-known service domains providing source-of-truth design information. - [PROMPT_INJECTION]: The skill's workflow and constraints are focused on technical quality and design consistency. No patterns indicative of attempts to bypass safety filters or override core agent instructions were detected.
- [DATA_EXFILTRATION]: No commands or logic for data exfiltration were found. The skill processes design inputs to generate local HTML files without unauthorized network transmission of sensitive information.
- [SAFE]: Indirect prompt injection surfaces exist in the ingestion of user-provided designs, but the skill's capabilities are restricted to visual code generation, which limits the potential impact of such vectors.
Audit Metadata