web-design-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches frontend libraries (React, Chart.js, D3.js) and assets from well-known services and content delivery networks, including jsDelivr, UNPKG, and Google Fonts. These are standard resources for building web prototypes and visualizations.
- [DYNAMIC_EXECUTION]: Interactive prototypes are supported via in-browser JSX transpilation using the Babel CDN. This allows the agent to create and run React-based UI components directly in the browser environment.
- [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external content, including existing codebases, screenshots, and product requirements. While this provides a potential path for indirect injection if these sources contain malicious data, the skill is focused on visual design and interactive prototyping.
- [COMMAND_EXECUTION]: The workflow includes instructions for the agent to use CLI tools like
yt-dlpandffmpegto capture official brand assets from video sources. This is a legitimate part of the asset-sourcing protocol described in the skill.
Audit Metadata