css-design-system
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from existing project style files and external documentation when configuring design systems. This creates a surface for indirect prompt injection. * Ingestion points: Existing style files and external documentation sites retrieved via search. * Boundary markers: None provided for delimited ingestion of untrusted data. * Capability inventory: Ability to write and update CSS files and preview.html across the project directory. * Sanitization: No sanitization or validation of external content is required before processing or generating styles.
- [DYNAMIC_EXECUTION]: The skill implements a self-modifying instruction pattern where the agent is told to rewrite the Settings YAML block within SKILL.md to persist configuration changes. This allows potentially untrusted user input to modify the agent's persistent instructions.
Audit Metadata