design-md

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: Audits local repository configuration and source files, such as package.json, tailwind.config.*, and globals.css, to extract design tokens. The information gathering is strictly local for documentation purposes, and no network exfiltration patterns were observed.
  • [COMMAND_EXECUTION]: Instructs the agent to create and update documentation files and a new agent skill file (.agents/skills/frontend-design/SKILL.md) using local templates. These actions represent standard file system management for repository setup.
  • [PROMPT_INJECTION]: The skill audits pre-existing repository documentation and source code, which provides an indirect prompt injection surface. However, the skill primarily summarizes this content into a new document and requires user approval for any new design proposals, limiting the impact of potentially malicious content in the source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 03:35 PM
Security Audit — agent-trust-hub — design-md