sheleg-design

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions direct the agent to run shell commands such as npx, npm install, and npm run build to set up design kits from the author's published package.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external code and assets from a package registry using the sheleg-design-skill tool and pulls data from external design reference tools like Lazyweb, Mobbin, and Refero.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting untrusted data from Figma files and external design platforms (documented in DESIGN_SYNC_BRIDGE.md, FIGMA_BRIDGE.md, and MOBILE_SURFACES.md). While the agent has shell execution capabilities, the skill incorporates boundary markers and explicit instructions to treat all fetched content strictly as data and ignore any embedded instructions (sanitization).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 10:45 AM
Security Audit — agent-trust-hub — sheleg-design