hig-doctor

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install external components from the 'raintree-technology/hig-doctor' GitHub repository using the 'npx skills add' command.
  • [COMMAND_EXECUTION]: Provides shell commands for installation and environment checking, specifically referencing the ~/.design-agent-skills/ directory. It also documents the use of the '!' command prefix for execution within compatible agent environments.
  • [PROMPT_INJECTION]: As a diagnostic tool that analyzes external UI source code and design documentation, the skill possesses an indirect prompt injection surface.
  • Ingestion points: Analysis of user-provided UI code and design files as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instruction-ignore warnings are defined in this stub.
  • Capability inventory: Capability to check local file existence and invoke specialized sub-skills for various HIG categories.
  • Sanitization: No sanitization or validation of the analyzed content is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — hig-doctor