frontend-design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains instructional Markdown content only. No evidence of obfuscation, malicious code, or unauthorized network activity was found during the analysis.- [COMMAND_EXECUTION]: The skill suggests using the standard npx shadcn@latest add command for UI component initialization. This involves running a well-known tool within a standard development environment.- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface by reading external project context from .tasks/domain.md.
  • Ingestion points: Instructions specify reading .tasks/domain.md for brand details and terminology.
  • Boundary markers: The agent is directed to extract specific, limited types of information (colors, roles, statuses), which serves as a natural constraint.
  • Capability inventory: The skill permits the agent to write and modify frontend source files (CSS, React).
  • Sanitization: Content is parsed and applied to UI tokens rather than being directly executed, reducing the risk of malicious payload triggering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:43 PM
Security Audit — agent-trust-hub — frontend-design