skills/mimukit/skills/designkit/Gen Agent Trust Hub

designkit

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to fetch and execute the @google/design.md package from the npm registry. This targets an official tool from a trusted organization for validating and exporting design tokens.
  • [COMMAND_EXECUTION]: Shell commands are executed via Bash to interact with git, gh (GitHub CLI), and npx. These are used for project auditing, version comparisons, and design system linting.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists via the extraction engine. • Ingestion points: UI code files (CSS, templates, and components) read via Read and Grep. • Boundary markers: Structured DESIGN.md specification. • Capability inventory: Bash, Write, Edit, Grep, Glob, Read. • Sanitization: Validation is performed by the official @google/design.md linter. This activity is required for the skill's primary function of deriving design tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:52 AM
Security Audit — agent-trust-hub — designkit