frontend-design
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches design specifications, icon registries, and metadata from several third-party sources not associated with the primary vendors or well-known organizations.
- File
references/brand-design-catalogue.mdfetches content from theVoltAgent/awesome-design-mdGitHub repository. - File
references/icon-sourcing.mdretrieves icon registry data from a repository under theglinckerGitHub account. - [REMOTE_CODE_EXECUTION]: The skill instructs the agent to install code directly from third-party domains via component registries. This pattern involves running installation tools that fetch and execute manifests from unverified sources.
- File
references/brainless/references/component-catalogue.mdusesbunx shadcn@latestto install components fromhttps://brainless.swerdlow.dev/. - Files
references/aceternity/README.mdandreferences/componentry/README.mdusepnpm dlx shadcn@latestto install fromhttps://ui.aceternity.com/andhttps://componentry.fun/respectively. - [COMMAND_EXECUTION]: The skill provides and instructs the agent to execute a suite of local Python scripts for design system generation and search operations.
- File
references/ui-ux-pro-max/README.mdprovides various commands for runningscripts/search.py. - [SAFE]: Several high-risk operations involve trusted organizations or recommended security practices.
- Fetches design guidelines from Vercel's official GitHub repository (
vercel-labs). - Uses
npxto execute utilities from the official Google repository (google-labs-code). - Secrets like
AI_GATEWAY_API_KEYare managed via local.envfiles as per standard security practices.
Audit Metadata