design-for-ai

Warn

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading a full package from an external GitHub repository (https://github.com/ryanthedev/design-for-ai) and a custom marketplace (ryanthedev/rtd-claude-inn).
  • [COMMAND_EXECUTION]: The SKILL.md and stub.yaml files provide explicit instructions for the agent to execute shell-like commands (/plugin marketplace add and /plugin install) to provision external software.
  • [REMOTE_CODE_EXECUTION]: The provided installation workflow fetches and executes remote code from an unverified third-party source, which allows for the execution of arbitrary scripts during the installation phase.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 20, 2026, 01:24 PM
Security Audit — agent-trust-hub — design-for-ai