mj-design
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches library dependencies including React, Babel, and Popmotion from unpkg.com, which is a well-known CDN for hosting open-source packages. These scripts are utilized within the generated HTML prototypes to enable interactive features and runtime JSX compilation.
- [DATA_EXFILTRATION]: The skill uses standard browser APIs such as
window.parent.postMessageandlocalStorage. These are used legitimately for a 'Tweaks Panel' feature and to persist playback states for slide decks, representing standard development patterns for interactive prototypes. - [PROMPT_INJECTION]: As a design tool, the skill is designed to ingest user-provided context such as screenshots and brand assets to inform its design decisions. This represents the intended functional surface of the tool and does not exhibit malicious override patterns.
Audit Metadata