extract-design-system

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the extract-design-system package and the Playwright browser automation tool via npx. Playwright is a well-known service used for browser-based automation tasks.
  • [COMMAND_EXECUTION]: Executes shell commands to install Chromium dependencies and run the extraction utility as part of the intended project initialization workflow.
  • [PROMPT_INJECTION]: The skill processes content from user-provided websites, creating an indirect prompt injection surface. This is managed by explicit safety boundaries in SKILL.md that instruct the agent to treat extracted content as untrusted, review the output, and require user confirmation before making any project changes. Evidence: 1. Ingestion points: normalized.json in SKILL.md; 2. Boundary markers: Safety instructions in SKILL.md regarding untrusted input; 3. Capability inventory: npx subprocess calls in SKILL.md and workflow.md; 4. Sanitization: Explicit confirmation requirements before file modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 05:06 PM
Security Audit — agent-trust-hub — extract-design-system