web-design-guidelines

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches design guidelines from Vercel Labs' official GitHub repository. This is an expected behavior for retrieving the latest standards from the developer's infrastructure.
  • [PROMPT_INJECTION]: The skill incorporates instructions from a remote source to guide its review logic. This represents an indirect prompt injection surface.
  • Ingestion points: Remote markdown file referenced in the 'Guidelines Source' section of SKILL.md.
  • Boundary markers: Absent; no delimiters or warnings are used to isolate external instructions from the skill's own logic.
  • Capability inventory: The skill is limited to reading local files and formatting text output; no capabilities for code execution, system modification, or network exfiltration were identified.
  • Sanitization: None; external content is used directly to define rules and output formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:17 PM
Security Audit — agent-trust-hub — web-design-guidelines