hmos-design-visual-mobile

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions and component templates rely entirely on local repository assets, referencing theme tokens and static resources via relative paths.
  • [EXTERNAL_DOWNLOADS]: Documentation and metadata files (e.g., hmsymbol-map.json) contain reference links to official Huawei developer resources on developer.huawei.com. These are recognized as well-known service domains providing source-of-truth design information.
  • [PROMPT_INJECTION]: The skill's workflow and constraints are focused on technical quality and design consistency. No patterns indicative of attempts to bypass safety filters or override core agent instructions were detected.
  • [DATA_EXFILTRATION]: No commands or logic for data exfiltration were found. The skill processes design inputs to generate local HTML files without unauthorized network transmission of sensitive information.
  • [SAFE]: Indirect prompt injection surfaces exist in the ingestion of user-provided designs, but the skill's capabilities are restricted to visual code generation, which limits the potential impact of such vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:17 AM
Security Audit — agent-trust-hub — hmos-design-visual-mobile