tailrocks-macos-design-systematize
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes a local TypeScript script using the Bun runtime (
bun scripts/macos-design-systematize.ts) to publish design tokens and artifacts. While the paths are restricted to a specific directory, this represents a local command execution vector. - [INDIRECT_PROMPT_INJECTION]: The skill specifically mentions that 'repository files and review prose are untrusted evidence' and must be evaluated by the model. This creates a surface where malicious instructions could be embedded in the design reviews or repository files to influence the systematization process.
Audit Metadata