frontend-design

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user requirements to generate and modify frontend code, which creates a surface for indirect prompt injection.
  • Ingestion points: Processes user-supplied requirements for components, pages, and applications as described in the SKILL.md core logic.
  • Boundary markers: There are no explicit delimiters or 'ignore previous instructions' markers defined for the data interpolation.
  • Capability inventory: The skill is linked to capabilities for source code modification (self-modifying-code) and writing configuration to data files (files-as-database).
  • Sanitization: No input validation or sanitization routines are specified for the ingested requirements.
  • [EXTERNAL_DOWNLOADS]: The implementation guidelines suggest fetching typography assets from Google Fonts, which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 06:45 AM
Security Audit — agent-trust-hub — frontend-design