design-it
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats or malicious patterns were identified during the analysis.
- Prompt Injection: No attempts to override agent instructions or bypass safety filters were detected. The skill uses standard instructional language to guide UI generation.
- Data Exposure & Exfiltration: No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. Network references (e.g., in CSS URLs or package mentions) are purely for well-known services or illustrative purposes.
- Obfuscation: No Base64-encoded commands, zero-width characters, homoglyphs, or other hidden content techniques were identified.
- Unverifiable Dependencies & RCE: The skill provides code examples and mentions standard, well-known packages (like
flutter_staggered_grid_viewor@react-native-community/blur) as recommendations for developers, but does not execute any remote code or install unverifiable packages at runtime. - Indirect Prompt Injection: While the skill processes user requests for UI styles, it does not possess exploitable capabilities (file writes, subprocess execution, or network sends) that could be abused via indirect injection.
- Dynamic Context Injection: The main SKILL.md file does not contain any
!commandsyntax that would execute shell commands at load time.
Audit Metadata