design-it

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security threats or malicious patterns were identified during the analysis.
  • Prompt Injection: No attempts to override agent instructions or bypass safety filters were detected. The skill uses standard instructional language to guide UI generation.
  • Data Exposure & Exfiltration: No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. Network references (e.g., in CSS URLs or package mentions) are purely for well-known services or illustrative purposes.
  • Obfuscation: No Base64-encoded commands, zero-width characters, homoglyphs, or other hidden content techniques were identified.
  • Unverifiable Dependencies & RCE: The skill provides code examples and mentions standard, well-known packages (like flutter_staggered_grid_view or @react-native-community/blur) as recommendations for developers, but does not execute any remote code or install unverifiable packages at runtime.
  • Indirect Prompt Injection: While the skill processes user requests for UI styles, it does not possess exploitable capabilities (file writes, subprocess execution, or network sends) that could be abused via indirect injection.
  • Dynamic Context Injection: The main SKILL.md file does not contain any !command syntax that would execute shell commands at load time.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:36 AM
Security Audit — agent-trust-hub — design-it