audit-uiux-design-system
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
grepandgloboperations to scan local project files (likepackage.json,.tsx, and.css) to identify used frameworks, component libraries, and design tokens. This is standard read-only analysis for an auditing tool. - [EXTERNAL_DOWNLOADS]: Uses the
user-firecrawlandcontext7MCP tools to fetch design documentation and visual benchmarks from the web. These downloads are restricted to the context of the design audit. - [PROMPT_INJECTION]: The skill processes content from external web searches and local files without explicit boundary markers or sanitization. This creates a surface for indirect prompt injection where malicious content in a searched webpage or project file could attempt to influence the agent. However, this risk is inherent to any data-processing skill and is not an active exploit in the code itself.
Audit Metadata