domain-design
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The branding onboarding feature described in
references/onboarding.mduses theagent-browsertool to fetch external website content for style extraction. This is a legitimate functional requirement that includes a mandatory review step where the agent must propose changes and wait for user approval before writing to the configuration file, effectively mitigating the risk of indirect prompt injection. - [SAFE]: The skill uses Google Fonts as an external resource for typography in the generated artifacts, which is a well-known and trusted service.
- [SAFE]: The skill does not execute arbitrary shell commands, access sensitive local system files, or attempt to exfiltrate data. All operations are focused on generating documentation artifacts based on user input.
- [SAFE]: No obfuscation, persistence mechanisms, or credential-harvesting patterns were found in the instructions or reference templates.
Audit Metadata