Security risk report for @forgecat/contains-studio_agents_design v0.1.2
Source Integrity
Low
Profile references a legitimate public GitHub repository (contains-studio/agents) with clear attribution and version tracking.
No supply-chain manipulation, typosquatted dependencies, or attacker-controlled package references are present.
Agent Intent
Low
Content describes legitimate design agent roles (brand guardian, UI designer, UX researcher, visual storyteller, whimsy injector) with standard professional responsibilities and best practices.
No instructions to ignore system prompts, read credentials, exfiltrate data, install remote payloads, or reveal hidden instructions are present.
No guidance poisoning: recommendations for tools (Figma, Tailwind CSS, standard design patterns) are well-known, legitimate, and security-neutral; no typosquatted packages or backdoored templates are embedded.
Content is descriptive documentation of design workflows, not manipulative instructions targeting the AI agent.
Details
Evidence
All agent descriptions focus on design responsibilities: 'Keep visual identity consistent', 'Design interfaces developers can actually build', 'Turn user insights into product improvements', etc.
Tool recommendations are standard industry tools: Figma, Tailwind CSS, Heroicons, Radix UI, Hotjar, Maze—all legitimate and widely used.
No instructions to bypass security, read files like ~/.ssh or ~/.aws, or transmit data to external hosts.
Permissions
Low
Declared tools (Write, Read, MultiEdit, WebSearch, WebFetch, Grep, Glob) are standard, low-risk utilities appropriate for design documentation and research tasks.
Tool usage is scoped to design workflows: reading/writing design documentation, searching for design references, fetching design resources—no shell execution, file deletion, or unrestricted filesystem access.
No alwaysApply=true rules with broad globs; no high-risk categories (shell, file_delete, file_mutate) are requested.