ui-standards-tokens
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses strong instructional language (e.g., "Iron Law") to enforce design consistency and token usage. No patterns of malicious prompt injection, system prompt extraction, or safety filter bypasses were detected. Phrases like "Ignore previous instructions" or "DAN" are absent.- [DATA_EXFILTRATION]: No network operations, hardcoded credentials, or sensitive file path access are present in the skill files. The skill is scoped to the
Readtool for accessing internal reference documentation. There are no patterns suggesting data harvesting or external transmission.- [REMOTE_CODE_EXECUTION]: The skill contains static documentation and code snippets for developer reference. There are no mechanisms for downloading or executing remote code, and no suspicious external dependencies or unpinned packages are listed.- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or privilege escalation patterns (such assudoorchmod) are present in the scripts or instructions. The "Hookify" rules described in the metadata refer to local linting configurations rather than executable shell scripts.- [SAFE]: The skill promotes secure and standard coding practices by encouraging the use of design tokens over hardcoded values and providing clear accessibility guidelines for touch targets and focus management.
Audit Metadata