scss
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill provides static reference material for SCSS best practices, including module system usage and design tokens.
- [COMMAND_EXECUTION]: The skill mentions standard development commands (e.g.,
sass,npm run build) inreferences/workflows.md. These are documented as manual verification steps for the user to perform and do not involve autonomous execution or dangerous shell piping by the agent. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided styling code for review and refactoring. However, it lacks exploitable capabilities such as network access, file-system modification, or dynamic code execution, rendering the surface area for indirect injection benign.
Audit Metadata