frontend-design

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches design specifications, icon registries, and metadata from several third-party sources not associated with the primary vendors or well-known organizations.
  • File references/brand-design-catalogue.md fetches content from the VoltAgent/awesome-design-md GitHub repository.
  • File references/icon-sourcing.md retrieves icon registry data from a repository under the glincker GitHub account.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to install code directly from third-party domains via component registries. This pattern involves running installation tools that fetch and execute manifests from unverified sources.
  • File references/brainless/references/component-catalogue.md uses bunx shadcn@latest to install components from https://brainless.swerdlow.dev/.
  • Files references/aceternity/README.md and references/componentry/README.md use pnpm dlx shadcn@latest to install from https://ui.aceternity.com/ and https://componentry.fun/ respectively.
  • [COMMAND_EXECUTION]: The skill provides and instructs the agent to execute a suite of local Python scripts for design system generation and search operations.
  • File references/ui-ux-pro-max/README.md provides various commands for running scripts/search.py.
  • [SAFE]: Several high-risk operations involve trusted organizations or recommended security practices.
  • Fetches design guidelines from Vercel's official GitHub repository (vercel-labs).
  • Uses npx to execute utilities from the official Google repository (google-labs-code).
  • Secrets like AI_GATEWAY_API_KEY are managed via local .env files as per standard security practices.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — frontend-design