design-system
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites (via competitor research) and local codebase files (CSS, Tailwind, etc.) and uses this content to influence its generated output.
- Ingestion points: Processes external website content via the browser MCP tool and reads local styling files (CSS, JS, etc.).
- Boundary markers: The instructions do not define boundary markers or explicit safety guidelines for the agent to ignore potentially malicious instructions embedded within the codebase or competitor site content.
- Capability inventory: The skill is capable of writing multiple file types including markdown, JSON, and HTML to the local file system.
- Sanitization: No data validation or sanitization routines are specified for content extracted from external or local sources before it is incorporated into generated files.
- [DYNAMIC_EXECUTION]: The skill generates interactive HTML preview pages based on extracted design tokens.
- Evidence: The 'Mode 1: Generate Design System' instructions command the agent to 'Create an interactive HTML preview page (self-contained, no deps)' using data extracted from the codebase and external research.
Audit Metadata