skills/nexu-io/open-design/token-map/Gen Agent Trust Hub

token-map

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests design token data from external sources, which represents an indirect prompt injection surface.
  • Ingestion points: The skill reads figma/tokens.json and code/tokens.json as primary inputs (SKILL.md).
  • Boundary markers: The instructions provide clear boundaries by stating the agent must not "invent target tokens silently" and must use unmatched.json for human auditing.
  • Capability inventory: The skill is capable of writing multiple JSON files to the local project-cwd/token-map/ directory.
  • Sanitization: The skill employs semantic role inference and evidence-based mapping logic to validate the role of anonymous tokens before they are accepted into the target system.
  • [SAFE]: The skill is authored by Open Design and its external references point to official vendor infrastructure on GitHub (github.com/nexu-io). No unauthorized network access, credential exposure, or persistence mechanisms were detected. The file system operations are localized to the design migration task.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:19 PM
Security Audit — agent-trust-hub — token-map