skeleton-ui
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches component documentation from skeleton.dev, the official website for the Skeleton UI framework. This is a well-known service and is considered safe under the trusted source guidelines.
- [PROMPT_INJECTION]: The skill uses the webfetch tool to ingest external data, which creates a surface for indirect prompt injection. However, since the source is official documentation and this is essential for the skill's primary purpose of providing up-to-date framework information, the risk is negligible.
- Ingestion points: skeleton.dev/llms.txt (referenced in SKILL.md).
- Boundary markers: Absent.
- Capability inventory: Code generation for UI components.
- Sanitization: Absent.
Audit Metadata