design-system-governor

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is limited to UI design governance and does not exhibit any patterns associated with prompt injection, data exfiltration, or remote code execution.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses local project files such as tailwind.config.js and tokens.json. These operations are essential for its stated purpose of design auditing and do not involve sensitive system directories, credentials, or network transmission.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted project files to generate design documentation, it lacks the necessary capabilities (such as shell access or network tools) to enable a successful attack chain. The injection surface is limited to visual configuration changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:00 PM
Security Audit — agent-trust-hub — design-system-governor