web-design-guidelines
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): Fetches guidelines from vercel-labs/web-interface-guidelines. The organization is trusted, so the risk of malicious instruction injection from the source is minimized.
- PROMPT_INJECTION (LOW): Potential for indirect prompt injection as the skill processes untrusted user files. Evidence: 1. Ingestion points: user-provided files; 2. Boundary markers: none; 3. Capability inventory: File reading and WebFetch; 4. Sanitization: none.
Audit Metadata