design-design-systems
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Multiple reference files (e.g., architecture-patterns.md, security-best-practices.md, deployment-pipelines.md) contain instructions attempting to constrain the agent's persona to an 'expert' level and define a narrow target audience ('strictly intended for Staff+ Engineers'). This persona steering can influence the model's tone and permissiveness beyond the intended skill boundaries.\n- [PROMPT_INJECTION]: The skill package includes over 1,200 sections of highly repetitive technical filler text across eight reference files. This anomalous volume of jargon related to kernel syscalls, eBPF, and distributed systems is irrelevant to the stated purpose of Design Systems and functions as a context-window bloat attack, potentially used to distract the model or bypass safety constraints through excessive irrelevant context.\n- [NO_CODE]: No executable scripts (.sh, .py, .js, .rb) or configuration files that trigger runtime code execution were found in the skill folder. The package consists entirely of markdown files.\n- [SAFE]: The primary instructions in SKILL.md regarding design tokens, component architecture, and governance follow standard UI/UX engineering best practices and contain no malicious instructions.
Audit Metadata