tailwind-v4

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Unverifiable Dependencies (LOW): The skill recommends installing several npm packages including 'tailwindcss', '@tailwindcss/vite', and 'rollup-plugin-visualizer'. Although these are standard industry tools, they are not on the restricted 'Trusted GitHub Organizations' list.
  • Command Execution (LOW): The setup and migration guides provide shell commands for package management and project builds (e.g., 'npm install', 'npm run build'). These are standard for frontend development but involve command execution.
  • Indirect Prompt Injection (LOW): The skill presents a surface for indirect prompt injection (Category 8) as it is designed to process and refactor user-provided project files. 1. Ingestion points: user project files. 2. Boundary markers: absent. 3. Capability inventory: code generation and output. 4. Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:37 PM