web-design-guidelines

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMMETADATA_POISONINGEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill metadata incorrectly identifies 'vercel' as the author, which conflicts with the actual author context ('calesthio'). Such discrepancies are deceptive and can lead users to misplace their trust based on vendor reputation.- [EXTERNAL_DOWNLOADS]: The skill fetches fresh guidelines and rules from Vercel Labs' official GitHub repository before performing reviews.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from remote URLs and local files, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Fetches a markdown file from a remote GitHub repository and reads local code files specified by the user.
  • Boundary markers: There are no explicit delimiters or specific instructions provided to the agent to disregard embedded commands within the fetched content.
  • Capability inventory: The skill utilizes WebFetch for network operations and possesses read access to the local file system.
  • Sanitization: Static instructions do not define any validation or sanitization routines for the content ingested from external sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 12:20 AM