design-style-installer
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches design tokens and configuration files (such as tokens.json and tailwind.tokens.js) from the author's GitHub repository at OneWave-AI/open-agent-stack.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute project build commands during the verification phase of the design installation.\n- [PROMPT_INJECTION]: The skill processes external W3C-format design tokens which presents a surface for indirect prompt injection.\n
- Ingestion points: The skill fetches remote or local token files and configuration scripts from external sources or user-provided paths.\n
- Boundary markers: No explicit delimiters or isolation instructions are provided to the agent for processing external data.\n
- Capability inventory: The skill has file system write access and shell execution capabilities to apply and verify styles.\n
- Sanitization: There are no instructions for validating or sanitizing the content of the ingested design files.
Audit Metadata