playful-devtool-ui

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation and instructional resource for UI design. Analysis of the instructions, style guides, and prompt templates revealed no malicious behavior, hardcoded credentials, or unauthorized command executions. The role-playing instructions define a professional persona and do not attempt to bypass agent safety filters or exfiltrate data.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process user-provided screenshots, URLs, and source code (referenced in SKILL.md) for auditing and restyling tasks. Ingestion points: User-supplied code and URL content. Boundary markers: None explicitly defined to delimit user content from instructions. Capability inventory: Generation of Tailwind CSS and React/HTML code. Sanitization: No specific input sanitization or validation logic is present. While this configuration allows the processing of potentially adversarial content embedded in user-supplied data, the skill's specific focus on visual auditing and structured rubrics acts as a logical constraint, and the severity is considered safe given it is inherent to the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 10:10 AM
Security Audit — agent-trust-hub — playful-devtool-ui