skills/johnlindquist/claude/design/Gen Agent Trust Hub

design

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external file data that could potentially contain malicious instructions.
  • Ingestion points: Contents of src/styles/tokens.css and src/styles/typography.css are read into the agent's context during design audits.
  • Boundary markers: The file contents are interpolated directly into the prompt for the gemini CLI without protective delimiters or instructions to ignore embedded text.
  • Capability inventory: The skill invokes the gemini command-line tool to process the ingested data.
  • Sanitization: No validation or filtering is performed on the CSS content before interpolation.
  • [COMMAND_EXECUTION]: The skill utilizes standard system utilities (cat, jq) and the gemini CLI to transform JSON tokens into CSS, JS, and SCSS formats and to perform design audits. These actions are consistent with the skill's primary purpose of design system management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:28 PM
Security Audit — agent-trust-hub — design