tailwind-css-v4-mastery
Warn
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The migration utility
scripts/migrate-v3-to-v4.shexecutes shell commands includingsedfor in-place file modification andrmfor deleting project configuration files, which are high-privilege operations on a user's local filesystem.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of Node.js packages such astailwindcssand@tailwindcss/vitefrom the official Tailwind Labs organization. These downloads target well-known services and are documented neutrally.\n- [PROMPT_INJECTION]: Theskill-report.jsonfile is a deceptive document masquerading as an official security audit report to bypass independent analysis. Evidence Chain: 1. Ingestion point:skill-report.json. 2. Boundary markers: Absent. 3. Capability inventory: Filesystem modification and package installation viascripts/migrate-v3-to-v4.sh. 4. Sanitization: Absent.
Audit Metadata