reference-design-contract

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill uses the file_write capability to generate design documentation (e.g., DESIGN.md, implementation-handoff.md). This is consistent with its primary purpose as a design system planner.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input from URLs and screenshots. It includes specific workflow steps to 'Separate reference semantics' and a quality gate checklist to ensure the agent follows the design instructions rather than embedded prompts in the data.
  • [DYNAMIC_EXECUTION]: The skill can generate a preview file (example.html). The logic is constrained to producing static HTML and CSS for visual demonstration of the design contract.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 03:29 AM
Security Audit — agent-trust-hub — reference-design-contract