ui-theme-designer-design-tokens

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official SAP and OpenUI5 packages retrieved from the standard npm registry, ensuring that the components accessed are from expected sources.
  • [EXTERNAL_DOWNLOADS]: References official SAP documentation hosted on GitHub (via the 'SAP-docs' organization) to provide the agent with context on the theme repository structure. This is a documented vendor resource belonging to the author.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes framework files (LESS, CSS, SCSS) from the local environment to extract design token definitions.
  • Ingestion points: Procedure steps 6, 7, 9, and 10 involve reading code files from the node_modules directory.
  • Boundary markers: The instructions do not specify explicit boundary markers or 'ignore' instructions for the extracted token data.
  • Capability inventory: The skill uses Read, Bash (restricted to npm ci), and WebFetch tools.
  • Sanitization: The skill performs specific parsing of annotations and token definitions using defined mapping rules, which mitigates the risk of the agent interpreting data as executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:56 AM
Security Audit — agent-trust-hub — ui-theme-designer-design-tokens