design-systems

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Found in SKILL.md. The skill includes a 'Companion check' section that instructs the agent to execute a shell command (ls) to list contents of various local skill directories such as ~/.claude/skills/ to determine the environment state.
  • [PROMPT_INJECTION]: The 'Companion check' mechanism introduces an indirect prompt injection surface by requiring the agent to ingest and act upon raw output from the local filesystem (the results of the ls command).
  • [EXTERNAL_DOWNLOADS]: Found in SKILL.md and README.md. The skill references and encourages the installation of several companion skills and development utilities (like Storybook and Style Dictionary) from the 'AbsolutelySkilled' vendor using package managers like npm and npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — design-systems