design-system

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites (via competitor research) and local codebase files (CSS, Tailwind, etc.) and uses this content to influence its generated output.
  • Ingestion points: Processes external website content via the browser MCP tool and reads local styling files (CSS, JS, etc.).
  • Boundary markers: The instructions do not define boundary markers or explicit safety guidelines for the agent to ignore potentially malicious instructions embedded within the codebase or competitor site content.
  • Capability inventory: The skill is capable of writing multiple file types including markdown, JSON, and HTML to the local file system.
  • Sanitization: No data validation or sanitization routines are specified for content extracted from external or local sources before it is incorporated into generated files.
  • [DYNAMIC_EXECUTION]: The skill generates interactive HTML preview pages based on extracted design tokens.
  • Evidence: The 'Mode 1: Generate Design System' instructions command the agent to 'Create an interactive HTML preview page (self-contained, no deps)' using data extracted from the codebase and external research.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:58 PM
Security Audit — agent-trust-hub — design-system