form-brief
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill employs a 'closed vocabulary' strategy for resolving design dimensions like colors, typography, and density. This ensures that only validated hex codes and font stacks from hardcoded tables are used in the generated files, mitigating risks of arbitrary code or style injection through the design brief.
- [SAFE]: The inclusion of tools such as
Bash,Write, andEditin the frontmatter is appropriate for the skill's function as a documentation generator. The instructions do not involve any suspicious or automated execution of shell commands; they focus on structured text generation and file creation based on user interaction. - [SAFE]: All external references, such as the repository and author URL, point to the vendor's own infrastructure (tonone-ai). There are no attempts to download or execute code from untrusted third-party sources or hidden domains.
- [SAFE]: The skill does not exhibit any patterns related to persistence, credential harvesting, or data exfiltration. The process is transparent, relying on the agent to resolve values into a human-readable
DESIGN.mdfile within the local workspace.
Audit Metadata