tailwind-css-v4-mastery

Warn

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The migration utility scripts/migrate-v3-to-v4.sh executes shell commands including sed for in-place file modification and rm for deleting project configuration files, which are high-privilege operations on a user's local filesystem.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of Node.js packages such as tailwindcss and @tailwindcss/vite from the official Tailwind Labs organization. These downloads target well-known services and are documented neutrally.\n- [PROMPT_INJECTION]: The skill-report.json file is a deceptive document masquerading as an official security audit report to bypass independent analysis. Evidence Chain: 1. Ingestion point: skill-report.json. 2. Boundary markers: Absent. 3. Capability inventory: Filesystem modification and package installation via scripts/migrate-v3-to-v4.sh. 4. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 4, 2026, 11:17 AM
Security Audit — agent-trust-hub — tailwind-css-v4-mastery