design-system-governance

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch and install content from a third-party GitHub repository (github.com/Owl-Listener/designer-skills) using the npx skills add command.
  • [REMOTE_CODE_EXECUTION]: By recommending the execution of npx skills add from an unverified external source, the skill facilitates the download and execution of remote code that has not been audited.
  • [COMMAND_EXECUTION]: The 'Decision tree' section contains shell commands (grep, npx) designed to be executed by the agent to manage the installation of external components, and it explicitly suggests using the !command syntax to run these actions directly.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 01:28 PM
Security Audit — agent-trust-hub — design-system-governance