makepad-font

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard technical documentation and code examples for font rendering in the Makepad UI framework. The reference to an external URL (crates.io) is a link to an official, well-known package registry for the Rust programming language.
  • [PROMPT_INJECTION]: The skill uses phrases like 'CRITICAL: Use for' and 'IMPORTANT: Documentation Completeness Check'. While these match common injection patterns, they are used here in a benign, instructional context to guide the AI's information retrieval and are not attempts to bypass safety filters or override core instructions.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or network exfiltration commands were detected. The link provided is a standard informational link.
  • [REMOTE_CODE_EXECUTION]: No package installation commands or remote code execution patterns were found. The code blocks contain Rust struct definitions and DSL snippets for UI development.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local reference files (./references/font-system.md). While this is a data ingestion point, the skill's purpose is purely informative regarding typography and does not expose dangerous capabilities like subprocess execution or file system writes that could be abused via malicious content in those files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:22 AM
Security Audit — agent-trust-hub — makepad-font