frontend-design

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill processes untrusted user requirements to generate frontend code, creating a potential surface for indirect prompt injection.
  • Ingestion points: User requirements for components, pages, or applications (SKILL.md).
  • Boundary markers: Absent; user input is interpolated into the creative process without delimiters or instructions to ignore embedded commands.
  • Capability inventory: Generates text-based code (HTML/CSS/JS, React, Vue). The skill itself does not have file-system access, network capabilities, or command execution privileges.
  • Sanitization: Absent; the instructions do not specify any validation or filtering of user-provided context before code generation.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 01:05 PM