design-system-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates the generation of design system artifacts including Markdown documentation, CSS style tokens, and static HTML examples. Analysis of the instructional content and templates shows no evidence of malicious intent, unauthorized command execution, or network exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an interview-based requirement gathering process in guides/01-interview-procedure.md where user-provided "Non-negotiables" are transcribed verbatim into the system's core documentation (00-design-brief.md). This creates a surface for indirect prompt injection if the resulting documentation is processed by other autonomous agents with executable capabilities.
  • Ingestion points: User interview responses collected via the procedure in guides/01-interview-procedure.md.
  • Boundary markers: Absent. User input is interpolated directly into generated Markdown files without defensive delimiters.
  • Capability inventory: File writing and directory creation at user-specified target paths (e.g., library/knowledge-base/) as described in SKILL.md.
  • Sanitization: No sanitization is performed on user input strings used in the generated documentation.
  • [DATA_EXPOSURE]: The research/research-plan.md file includes an internal file path (/sessions/gifted-nice-dijkstra/mnt/uploads/ux-ui.zip) referencing a source archive used during the skill's development. This is documented neutrally as a reference to the developer's research environment and does not pose a security risk to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:22 AM
Security Audit — agent-trust-hub — design-system-weapon