extract

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a purely functional workflow for code refactoring and design system maintenance.
  • [PROMPT_INJECTION]: While the skill uses directive language such as 'CRITICAL', 'IMPORTANT', and 'NEVER', these are applied within the context of design system best practices (e.g., asking before creating a new system, ensuring accessibility). They do not attempt to bypass AI safety guardrails or override system-level instructions.
  • [DATA_EXPOSURE]: The skill instructs the agent to search local source code for UI patterns and hard-coded values. It does not target sensitive directories like .ssh, .aws, or environment variables, nor does it contain any hardcoded credentials.
  • [REMOTE_CODE_EXECUTION]: There are no commands for downloading external scripts, installing unverified packages, or executing code from remote sources.
  • [COMMAND_EXECUTION]: The instructions suggest using standard search tools like grep to locate code patterns, which is appropriate for the stated purpose of code analysis and refactoring.
  • [DATA_EXFILTRATION]: No network operations or external communication patterns were identified. The workflow is confined to analyzing and modifying local project files.
  • [OBFUSCATION]: The content is written in clear, plain-text markdown without any hidden characters, Base64 encoding, or homoglyph substitutions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — extract