design-style-installer

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches design tokens and configuration files (such as tokens.json and tailwind.tokens.js) from the author's GitHub repository at OneWave-AI/open-agent-stack.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute project build commands during the verification phase of the design installation.\n- [PROMPT_INJECTION]: The skill processes external W3C-format design tokens which presents a surface for indirect prompt injection.\n
  • Ingestion points: The skill fetches remote or local token files and configuration scripts from external sources or user-provided paths.\n
  • Boundary markers: No explicit delimiters or isolation instructions are provided to the agent for processing external data.\n
  • Capability inventory: The skill has file system write access and shell execution capabilities to apply and verify styles.\n
  • Sanitization: There are no instructions for validating or sanitizing the content of the ingested design files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — design-style-installer