audit-uiux-design-system

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses grep and glob operations to scan local project files (like package.json, .tsx, and .css) to identify used frameworks, component libraries, and design tokens. This is standard read-only analysis for an auditing tool.
  • [EXTERNAL_DOWNLOADS]: Uses the user-firecrawl and context7 MCP tools to fetch design documentation and visual benchmarks from the web. These downloads are restricted to the context of the design audit.
  • [PROMPT_INJECTION]: The skill processes content from external web searches and local files without explicit boundary markers or sanitization. This creates a surface for indirect prompt injection where malicious content in a searched webpage or project file could attempt to influence the agent. However, this risk is inherent to any data-processing skill and is not an active exploit in the code itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 11:19 AM
Security Audit — agent-trust-hub — audit-uiux-design-system