extract
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define a purely functional workflow for code refactoring and design system maintenance.
- [PROMPT_INJECTION]: While the skill uses directive language such as 'CRITICAL', 'IMPORTANT', and 'NEVER', these are applied within the context of design system best practices (e.g., asking before creating a new system, ensuring accessibility). They do not attempt to bypass AI safety guardrails or override system-level instructions.
- [DATA_EXPOSURE]: The skill instructs the agent to search local source code for UI patterns and hard-coded values. It does not target sensitive directories like
.ssh,.aws, or environment variables, nor does it contain any hardcoded credentials. - [REMOTE_CODE_EXECUTION]: There are no commands for downloading external scripts, installing unverified packages, or executing code from remote sources.
- [COMMAND_EXECUTION]: The instructions suggest using standard search tools like
grepto locate code patterns, which is appropriate for the stated purpose of code analysis and refactoring. - [DATA_EXFILTRATION]: No network operations or external communication patterns were identified. The workflow is confined to analyzing and modifying local project files.
- [OBFUSCATION]: The content is written in clear, plain-text markdown without any hidden characters, Base64 encoding, or homoglyph substitutions.
Audit Metadata