design-system-builder

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user descriptions, screenshots, and Figma links to generate structured metadata and instructions for downstream AI coding agents. Ingestion points: Figma metadata and user-provided style descriptions in SKILL.md. Boundary markers: The generated design-tokens.json and design-system.md files lack explicit delimiters or instructions to ignore embedded commands. Capability inventory: The skill writes JSON, CSS, Markdown, and HTML files to the working directory. Sanitization: No specific filtering or sanitization logic for ingested design text is described.
  • [EXTERNAL_DOWNLOADS]: The preview templates in the examples folder reference external assets from well-known services. Evidence: HTML files in the examples directory fetch typography from Google Fonts (fonts.googleapis.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:50 PM
Security Audit — agent-trust-hub — design-system-builder