loora-design-guide

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown documentation and a configuration file. It does not contain any executable scripts, shell commands, or obfuscated payloads.
  • [EXTERNAL_DOWNLOADS]: The skill references a remote MCP server (https://mcp.loora.design/mcp) in the agent configuration. This URL is the authoritative tool provider for the Loora design environment and is consistent with the skill's primary purpose.
  • [PROMPT_INJECTION]: The instructions include defensive guardrails that direct the agent to stop and report errors if specific tools are missing, rather than attempting to bypass safety filters or guess schemas. These are positive security practices for maintaining agent stability.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill uses structured design nodes and screenshot tools intended for design verification within the controlled Loora environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 05:24 PM
Security Audit — agent-trust-hub — loora-design-guide