tailwind-css
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains legitimate instructions for CSS styling and project configuration.
- [EXTERNAL_DOWNLOADS]: Mentions standard ecosystem packages such as tailwind-variants and tw-animate-css via official links.
- [COMMAND_EXECUTION]: Instructs the agent to run repository maintenance commands like lint and build checks.
- [INDIRECT_PROMPT_INJECTION]: The workflow involves inspecting rendered DOM content. 1. Ingestion point: SKILL.md (Workflow Step 5). 2. Boundary markers: Absent. 3. Capability inventory: File writing and build command execution (SKILL.md). 4. Sanitization: Absent. This creates a theoretical surface for indirect prompt injection, though it is not exploitable in this context.
Audit Metadata