design-canvas
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute standard shell commands like
lsandcatto inspect project directories such aspublic/,assets/, andbrand/, as well as configuration files liketailwind.config.*. These commands are used solely to gather design context for visual asset generation and are hardcoded, preventing user-controlled command injection. - [DATA_EXPOSURE]: The skill reads local design assets, theme documentation, and IDE rules (e.g.,
.cursor/rules/) to align new visual art with the existing brand identity. No network operations, external data requests, or exfiltration mechanisms are present.
Audit Metadata