ckm-design-system
Build Token-Driven Design Systems
Design systems drift when tokens, components, and presentation assets are handled separately. This skill provides token architecture, validators, and slide helpers for consistent implementation.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ckm-design-system" from https://skillstore.io/skills/nextlevelbuilder-ckm-design-system.md and its manifest at https://skillstore.io/api/skills/nextlevelbuilder-ckm-design-system/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ckm-design-system". Request a token plan for a dashboard product.
Expected outcome:
- A three-layer token map covering raw values, semantic aliases, and component-specific tokens.
- Recommended naming rules for colors, typography, spacing, shadows, and interaction states.
Using "ckm-design-system". Ask for a token compliance review of a frontend folder.
Expected outcome:
- A local audit summary listing hardcoded colors, pixel values, and rem values.
- Suggested replacements using color, spacing, radius, and typography token families.
Using "ckm-design-system". Ask for a branded presentation plan.
Expected outcome:
- A slide-by-slide structure with recommended layouts, copy formulas, chart types, and emotional pacing.
- Guidance for token-compliant slide styling and background image selection.
Security Audit
Medium RiskMost static findings are false positives from Markdown code fences, JavaScript template literals, CSV design vocabulary, dictionary key access, and fixed public resource URLs. Confirmed issues are local filesystem write/read risks in the token generator plus semantic risks in slide generation: unescaped HTML content and unrestricted output paths. No prompt-injection attempt was found in the reviewed skill files.
Confirmed security concerns (2)
Capability review items (6)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (76)
📁 Filesystem access (15)
🌐 Network access (28)
🔑 Env variables (6)
⚡ Contains scripts (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/nextlevelbuilder-ckm-design-system/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/nextlevelbuilder-ckm-design-system?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/nextlevelbuilder-ckm-design-system?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/nextlevelbuilder-ckm-design-system/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/nextlevelbuilder-ckm-design-system.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
nextlevelbuilder. (2026). ckm-design-system security audit report (audit version 4) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/nextlevelbuilder-ckm-design-system/audits/4BibTeX citation
@techreport{nextlevelbuilder-nextlevelbuilder-ckm-design-system-2026,
author = {nextlevelbuilder},
title = {ckm-design-system security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/nextlevelbuilder-ckm-design-system/audits/4},
note = {Author version 1.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ckm-design-system security audit report (audit version 4)"
version: "1.0.0"
type: report
authors:
- name: "nextlevelbuilder"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/nextlevelbuilder-ckm-design-system/audits/4"
identifiers:
- type: other
value: "skillstore:nextlevelbuilder-ckm-design-system:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Create a Token Architecture
Define primitive, semantic, and component tokens before teams implement themes, states, and variants.
Audit Token Compliance
Scan local source files and HTML assets for hardcoded values that should use design tokens.
Plan Branded Presentations
Use slide strategy, layout, copy, chart, and background references to plan consistent presentation decks.
Try These Prompts
Use ckm-design-system to outline primitive, semantic, and component tokens for a SaaS dashboard. Include color, typography, spacing, radius, and state tokens.
Use ckm-design-system to review my src directory for hardcoded design values. Summarize violations and suggest equivalent token categories.
Use ckm-design-system to convert my token JSON into CSS variables and a Tailwind color extension. Keep outputs inside the project assets directory.
Use ckm-design-system to plan a 10-slide investor deck with strategy, layout, typography, color treatment, chart choices, and token-compliant HTML output.
Best Practices
- Keep primitive values separate from semantic aliases and component tokens.
- Run validators on trusted project folders before reviewing or sharing generated outputs.
- Keep generated slides and token files in predictable asset directories.
Avoid
- Do not paste untrusted HTML or scripts into slide data used for generation.
- Do not run file-writing helpers with absolute paths or parent-directory traversal.
- Do not mix raw hex values with token references in production components.
Frequently Asked Questions
Can this skill create a full design system?
Does it support Tailwind?
Can it validate my code automatically?
Can it generate slide decks?
Does it require network access?
Is it safe for untrusted content?
Developer Details
Author
nextlevelbuilderLicense
MIT
Author version
v1.0.0
Skillstore revision
r1
Repository
https://github.com/nextlevelbuilder/ui-ux-pro-max-skill/tree/main/.claude/skills/design-system/Ref
62e2a730c5cd74eab4c7164309d810de660fcea3
Maintenance freshness
7/18/2026
Usage
6 downloads · 15 views