atomic-design-system-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from the local lib/ directory and pubspec.yaml which are external inputs that may contain instructions or malicious patterns targeting the AI auditor.
  • Ingestion points: The skill reads Dart source files and project configuration files from the local file system using find and grep commands.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions that might be embedded within the source code comments or metadata of the files being audited.
  • Capability inventory: The skill utilizes shell-based tools for static analysis, including find, grep, wc, and sort. It does not possess network access, file-write capabilities, or arbitrary code execution paths in its current configuration.
  • Sanitization: The skill does not perform sanitization or filtering of the file contents before they are processed by the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:23 PM
Security Audit — agent-trust-hub — atomic-design-system-auditor