reference-design-contract
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill uses the
file_writecapability to generate design documentation (e.g., DESIGN.md, implementation-handoff.md). This is consistent with its primary purpose as a design system planner. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input from URLs and screenshots. It includes specific workflow steps to 'Separate reference semantics' and a quality gate checklist to ensure the agent follows the design instructions rather than embedded prompts in the data.
- [DYNAMIC_EXECUTION]: The skill can generate a preview file (
example.html). The logic is constrained to producing static HTML and CSS for visual demonstration of the design contract.
Audit Metadata