design-stylecards

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill is a well-documented design utility that uses local, static assets and restricted file-system tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages its data ingestion surface by requiring the agent to match user intent against a local, versioned catalog (references/stylecards.md). It explicitly instructs the agent to avoid freehand generation and to paste values exactly, which minimizes the risk of arbitrary content injection during the code modification process.
  • [COMMAND_EXECUTION]: The skill utilizes standard file operation tools (Read, Edit, Write) to perform its core functions. All file operations are directed toward the user's project files and the skill's own reference data, with no evidence of unsafe subprocess execution or unauthorized system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:16 AM
Security Audit — agent-trust-hub — design-stylecards