design
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external file data that could potentially contain malicious instructions.
- Ingestion points: Contents of
src/styles/tokens.cssandsrc/styles/typography.cssare read into the agent's context during design audits. - Boundary markers: The file contents are interpolated directly into the prompt for the
geminiCLI without protective delimiters or instructions to ignore embedded text. - Capability inventory: The skill invokes the
geminicommand-line tool to process the ingested data. - Sanitization: No validation or filtering is performed on the CSS content before interpolation.
- [COMMAND_EXECUTION]: The skill utilizes standard system utilities (
cat,jq) and thegeminiCLI to transform JSON tokens into CSS, JS, and SCSS formats and to perform design audits. These actions are consistent with the skill's primary purpose of design system management.
Audit Metadata