skills/iwanhe/pandawa/epic-design/Gen Agent Trust Hub

epic-design

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes local utility scripts (scripts/inspect-assets.py and scripts/validate-layers.js) to perform image analysis and HTML validation. These scripts use standard libraries (Pillow for Python, built-in fs/path for Node.js) and do not perform network operations or access sensitive system data.\n- [EXTERNAL_DOWNLOADS]: The skill references well-known frontend animation and scrolling libraries (GSAP, Lenis) hosted on cdn.jsdelivr.net. JSDelivr is a standard, reputable CDN for serving open-source software, and these references are consistent with the skill's primary purpose of web design.\n- [COMMAND_EXECUTION]: The agent is instructed to run local analysis scripts on project assets and generated files. This is a common and safe pattern for development skills intended to automate quality assurance and asset preparation.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user briefs and project context files. The potential for prompt injection is mitigated by the skill's structured workflow, which requires the agent to plan and present its findings to the user for confirmation before generating code.\n- [SAFE]: The skill emphasizes security and accessibility best practices, specifically implementing prefers-reduced-motion to ensure the safety of users with vestibular disorders and providing guidelines for semantic HTML and ARIA attributes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — epic-design