skills/tonone-ai/tonone/form-brief/Gen Agent Trust Hub

form-brief

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill employs a 'closed vocabulary' strategy for resolving design dimensions like colors, typography, and density. This ensures that only validated hex codes and font stacks from hardcoded tables are used in the generated files, mitigating risks of arbitrary code or style injection through the design brief.
  • [SAFE]: The inclusion of tools such as Bash, Write, and Edit in the frontmatter is appropriate for the skill's function as a documentation generator. The instructions do not involve any suspicious or automated execution of shell commands; they focus on structured text generation and file creation based on user interaction.
  • [SAFE]: All external references, such as the repository and author URL, point to the vendor's own infrastructure (tonone-ai). There are no attempts to download or execute code from untrusted third-party sources or hidden domains.
  • [SAFE]: The skill does not exhibit any patterns related to persistence, credential harvesting, or data exfiltration. The process is transparent, relying on the agent to resolve values into a human-readable DESIGN.md file within the local workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — form-brief