audit
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Local Script Execution: The skill references a preflight script located in the internal user-context module. This execution is used to prepare the environment when local shell access is available, ensuring the auditing tools are correctly configured for the current task.
- External Data Ingestion: The skill is designed to process content from various external sources such as live websites, Figma boards, and code repositories.
- Ingestion points: Untrusted data enters the agent context via product URLs, Figma files, and codebase paths mentioned in
SKILL.md. - Boundary markers: There are no explicit delimiters or warnings to ignore instructions within the processed data mentioned in the provided instructions.
- Capability inventory: The skill uses browser automation for screen capture, file system access for saving evidence, shell execution for setup scripts, and the Figma API for board creation.
- Sanitization: No specific content sanitization or validation logic is defined in the instruction files for the external data being audited.
- Network and Service Integration: The skill performs network operations to access targeted URLs and interact with the Figma platform. These connections are necessary for capturing current product states and fulfilling the user's request for integrated reports.
- Local File Management: The skill maintains a workflow for saving, inspecting, and verifying screenshots locally. This practice ensures that audit evidence is validated by the agent before being committed to final reports or external services.
Audit Metadata