remember-design-system
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx -y @memi-design/cli@2.7.9to download and run the vendor's tool from npm. This is a vendor-owned resource for 'memi-design' and is documented as part of the skill's primary functionality.\n- [COMMAND_EXECUTION]: The CLI tool is executed with shell commands that include a user-supplied 'intent' string. This represents a command injection surface if the agent does not properly sanitize the task description before command generation.\n- [INDIRECT_PROMPT_INJECTION]: The agent ingests design brief data from the CLI tool's output to perform code edits. Evidence Chain: 1. Ingestion points: JSON output from theagent briefandtokenscommands; 2. Boundary markers: Absent; 3. Capability inventory: Repository-wide UI refactoring and file writing; 4. Sanitization: Absent.
Audit Metadata