design-system
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell commands (
ls,cat,grep,rg) used to inspect the local filesystem for existing design tokens and components. These commands are restricted to development directories (e.g.,src/components/ui/) and standard configuration files (package.json,tailwind.config.*). - [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface as it ingests and processes local project files to inform the agent's actions. While it lacks explicit boundary markers for untrusted data, the processing is limited to standard project files, and the capabilities are confined to local development tasks, presenting minimal risk.
Audit Metadata