frontend-engineer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains specific instructions designed to override potential system-level constraints, mandating the use of TailwindCSS through phrases like 'CRITICAL OVERRIDE' and 'MUST IGNORE'.
- [COMMAND_EXECUTION]: Several dynamic context injection placeholders (
!cat) are used in theSKILL.mdfile to execute shell commands at load time for incorporating shared protocols and configuration files. - [PROMPT_INJECTION]: The skill is designed to ingest and process external project artifacts, creating a surface for indirect prompt injection.
- Ingestion points:
api/openapi/*.yamland user story documentation. - Boundary markers: Absent from prompt templates.
- Capability inventory: Full file system access for code generation and shell command execution for testing (Playwright, Vitest).
- Sanitization: API response validation via Zod is implemented in the service layer, but no sanitization for ingested markdown or YAML documents is established.
Audit Metadata