ui-tokens

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for routine UI development tasks, specifically managing design tokens within a project. It interacts solely with local configuration files like tokens/*.json and css/*.css.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data (JSON/CSS files) and implements changes based on those contents. While it lacks explicit boundary markers for the data it reads, the scope is limited to UI token management, presenting a negligible risk factor.
  • [COMMAND_EXECUTION]: The skill documentation mentions placeholders such as $0, $1, and $ARGUMENTS, but these are used as descriptive labels for the skill's logic rather than instructions for direct shell execution or dynamic context injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:33 PM
Security Audit — agent-trust-hub — ui-tokens