ui-tokens
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for routine UI development tasks, specifically managing design tokens within a project. It interacts solely with local configuration files like
tokens/*.jsonandcss/*.css. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data (JSON/CSS files) and implements changes based on those contents. While it lacks explicit boundary markers for the data it reads, the scope is limited to UI token management, presenting a negligible risk factor.
- [COMMAND_EXECUTION]: The skill documentation mentions placeholders such as
$0,$1, and$ARGUMENTS, but these are used as descriptive labels for the skill's logic rather than instructions for direct shell execution or dynamic context injection.
Audit Metadata