loora-design-guide
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation and a configuration file. It does not contain any executable scripts, shell commands, or obfuscated payloads.
- [EXTERNAL_DOWNLOADS]: The skill references a remote MCP server (https://mcp.loora.design/mcp) in the agent configuration. This URL is the authoritative tool provider for the Loora design environment and is consistent with the skill's primary purpose.
- [PROMPT_INJECTION]: The instructions include defensive guardrails that direct the agent to stop and report errors if specific tools are missing, rather than attempting to bypass safety filters or guess schemas. These are positive security practices for maintaining agent stability.
- [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill uses structured design nodes and screenshot tools intended for design verification within the controlled Loora environment.
Audit Metadata