awesome-design-systems

Fail

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documentation in SKILL.md includes a curl command to download a file from an untrusted GitHub repository (alexpate/awesome-design-systems). It further instructs users to run local Python scripts (tools/parse.py and tools/build.py) to process this external content. This workflow could be exploited if the upstream repository is compromised.
  • [DATA_EXFILTRATION]: Automated scanners have identified a malicious URL within the skill's reference files. The URL https://blocks.cbrebuild.com/ (CBRE Blocks) is blacklisted and contributes to security alerts on references/all-systems.md and references/with-voice-and-tone.md.
  • [SAFE]: The majority of the skill's content is static documentation and links to well-known, legitimate design systems from major technology organizations.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/alexpate/awesome-design-systems/master/README.md - DO NOT USE without thorough review
  • CRITICAL: 2 infected file(s) detected - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 20, 2026, 03:16 PM
Security Audit — agent-trust-hub — awesome-design-systems