image-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local scripts such as 'python3 scripts/design_systems.py', 'scripts/contrast.py', 'node scripts/measure_render.mjs', and 'npm run verify'. These tools are used for design token validation and output verification within the local environment.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied images and screenshots. While this is an ingestion point for external data, the instructions focus on extracting stylistic properties (palette, spacing) rather than parsing or executing text content, which limits the attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:10 AM
Security Audit — agent-trust-hub — image-to-code