web-design-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches frontend libraries (React, Chart.js, D3.js) and assets from well-known services and content delivery networks, including jsDelivr, UNPKG, and Google Fonts. These are standard resources for building web prototypes and visualizations.
  • [DYNAMIC_EXECUTION]: Interactive prototypes are supported via in-browser JSX transpilation using the Babel CDN. This allows the agent to create and run React-based UI components directly in the browser environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external content, including existing codebases, screenshots, and product requirements. While this provides a potential path for indirect injection if these sources contain malicious data, the skill is focused on visual design and interactive prototyping.
  • [COMMAND_EXECUTION]: The workflow includes instructions for the agent to use CLI tools like yt-dlp and ffmpeg to capture official brand assets from video sources. This is a legitimate part of the asset-sourcing protocol described in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:34 PM
Security Audit — agent-trust-hub — web-design-engineer