mekari-taste
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a human-in-the-loop security model, explicitly requiring user confirmation of structural plans and wireframes before any code generation is triggered.
- [SAFE]: All design tokens, layout shells, and pattern references are hosted internally or within the vendor's own infrastructure (mekari.design), posing no external dependency risks.
- [SAFE]: The skill operates on a least-privilege basis, utilizing only the necessary tools for visualization and requirement analysis without accessing sensitive system files or credentials.
- [SAFE]: While the skill ingests untrusted data from Confluence URLs or user text, its functionality is limited to generating non-executable wireframes and markdown plans, effectively mitigating risks associated with indirect prompt injection.
Audit Metadata