ux-ui-agent-skillsBLOCK
Turn Claude into a senior design architect: DTCG tokens, 52 components, WCAG 2.2 AA-AAA, 138 design systems, any-framework code, and 50 objective gates that fail the build instead of faking success.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
aka XIAS**
Turn Claude into a Senior Design Architect — 15+ years of expertise in design systems, accessibility, and production-ready component engineering.
A comprehensive kit of structured instructions, design tokens, runnable skills, and 138 brand-grade design systems that turn Claude into a UX/UI expert agent — targeting any framework and any design system. Drop it into any project for consistent, accessible, token-driven design outputs, every time.
<img src=".github/images/hero.png" alt="XIAS - design-system doctrine for coding agents. 52 objective gates, 34 of which open a real browser: WCAG contrast in every state, axe roles and landmarks, keyboard, target size, reduced motion, no horizontal overflow at 280, token by intent, screen economy. 138 design systems, 52 component specs, 25 runnable skills, 14 DTCG token files, 16 framework adapters. Claude Code, Codex, Cursor, Copilot, Aider, MCP." width="900">
[](https://github.com/plugin87/ux-ui-agent-skills/releases) [](#license) [](#-accessibility-standards)
[](https://www.npmjs.com/package/ux-ui-agent-skills) [ and `${CLAUDE_SKILL_DIR}/../../../accessibility/aria-patterns.md`.
2. Check the mandatory P0 set per component: keyboard navigable, focus visible (≥3:1), screen-reader name/role/state, contrast (4.5:1 text / 3:1 UI), target size ≥24×24, no color-only signaling.
3. Verify WCAG 2.2 additions: Focus Not Obscured (2.4.11), Target Size (2.5.8), Accessible Authentication (3.3.8).
4. **Contrast — measure, don't eyeball.** For rendered HTML, RUN the real-render gates and report their actual output (CLAUDE.md → Verification Protocol): `node ${CLAUDE_SKILL_DIR}/../../../scripts/measure_render.mjs <file> [--dark]` (every text element) AND `node ${CLAUDE_SKILL_DIR}/../../../scripts/verify_states.mjs <file> [--dark]` (every interactive element in default/hover/focus — catches hover-state failures). For loose color pairs, `python3 ${CLAUDE_SKILL_DIR}/../../../scripts/contrast.py "<fg>" "<bg>"`. Never state a ratio you did not measure.
5. Check reduced-motion handling (`${CLAUDE_SKILL_DIR}/../../../taste/motion-choreography.md`).
## Output
A findings table: WCAG criterion (e.g. 1.4.3) · severity (P0/P1/P2) · what fails · specific fix. Confirm passes explicitly. Accessibility may never be traded for aesthetics.Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (13)
const read = () => page.$eval(sel, (el, a) => el.getAttribute(a), x.stateAttr);
const read = () => page.$eval(host, el => el.getAttribute('aria-activedescendant'));console.log(` 4. Set the MCP env vars (FIGMA_API_KEY, ...) in your shell. Never commit a secret.`);
console.log(`lint_intent: FAIL — token chosen by convenience, not by intent${dark ? ' [dark]' : ''}`);<h3 class="breakable">pk_live_51MZq8bK2eCx9vRt7WgYh3NdJfLpQaSzXcVbNmKjHgFdSaPoIuYtReWq</h3>
.mcp.example.json
for (const forbidden of ['spawnSync', 'execSync', 'spawn(', 'exec(', 'child_process']) {print("\nWrite them as ${CLAUDE_SKILL_DIR}/../../../<path>, or for a "const root = resolve(skillDir, '../../..');
`${skillDir} + ../../.. resolved to ${root}, not the project root`);const firstUse = text.indexOf('${CLAUDE_SKILL_DIR}/../../../');esbuild, playwright, react, react-dom
**Then start using** — open the project in **Claude Code** or any Claude-powered IDE. `CLAUDE.md` loads automatically, activating the agent persona with full access to every tokens / components / tast
Gates applied: no_behavioural_pass.
b0f99e285339full audit observations/trust-audit/skill/plugin87__ux-ui-agent-skills.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | b0f99e285339 | BLOCK | D | 69 | first audit |
Questions
What does the ux-ui-agent-skills skill do?
Turn Claude into a senior design architect: DTCG tokens, 52 components, WCAG 2.2 AA-AAA, 138 design systems, any-framework code, and 50 objective gates that fail the build instead of faking success.
Is ux-ui-agent-skills safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can ux-ui-agent-skills access on my machine?
The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.
Which assistants does ux-ui-agent-skills work with?
Its documentation mentions claude-code, codex, copilot, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (b0f99e285339), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.