project-design
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of Markdown documentation (SKILL.md and referenced guidelines). It contains no executable scripts (Python, JavaScript, Shell) or binary files, significantly reducing the attack surface.
- [EXTERNAL_DOWNLOADS]: The instructions guide the agent to reference well-known and trusted external resources, such as Google Fonts and reputable charting libraries (Chart.js, ECharts) via standard content delivery networks (CDNs). These are well-known services used for their intended purpose in web development.
- [PROMPT_INJECTION]: The skill includes logic for 'Design Dials' using UTC time and 'Priority Overrides' for user preferences. These are functional mechanisms designed to improve output variety and follow user instructions, not attempts to bypass security filters or override system-level safety protocols.
- [DATA_EXFILTRATION]: No patterns were detected that involve accessing sensitive local files (like .ssh or .aws credentials) or exfiltrating data to unknown remote servers.
- [SAFE]: The skill follows secure documentation practices, such as instructing the agent to define colors via CSS custom properties and advocating for standard accessibility and performance best practices (e.g., prefers-reduced-motion).
Audit Metadata