frontend-design
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses instructional markers like 'IMPORTANT' and 'CRITICAL', but these are used solely to emphasize design quality and adherence to aesthetic guidelines. They do not attempt to bypass safety filters or override the underlying agent's system instructions.
- [DATA_EXFILTRATION]: No patterns of hardcoded credentials, sensitive file access, or unauthorized network operations were identified. The skill focuses entirely on client-side frontend implementation.
- [REMOTE_CODE_EXECUTION]: The skill does not execute external scripts or download untrusted binaries. It mentions the 'Motion library' (Framer Motion) for React, which is a well-known and trusted package in the frontend ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect injection surface as it processes user-provided requirements to generate code.
- Ingestion points: User-provided frontend requirements (SKILL.md).
- Boundary markers: None present.
- Capability inventory: Generates HTML, CSS, JS, and React code.
- Sanitization: Not explicitly implemented within the skill instructions. This is a standard operational surface for a code-generation skill and is not accompanied by any malicious capabilities.
Audit Metadata