squad-frontend

Fail

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from Figma, API payloads, and research pages. It addresses this risk by including explicit instructions to treat such data as untrusted and by providing guidelines for XSS prevention and HTML sanitization. • Ingestion points: Figma MCP, API responses, and research content (SKILL.md, references/designer-gate-and-design-intake.md). • Boundary markers: Instructions advise treating external data as untrusted (SKILL.md). • Capability inventory: File system access, network API integration, and shell execution for builds/tests. • Sanitization: Includes specific instructions for XSS prevention and HTML sanitization (references/frontend-security-accessibility-and-performance.md).
  • [EXTERNAL_DOWNLOADS]: The skill references documentation for several popular frontend libraries, including shadcn-vue.com, which is a widely used community resource. Although automated scanners have flagged this domain, it is a recognized service in the frontend ecosystem.
  • [CREDENTIALS_UNSAFE]: The instructions contain strong security guidelines for credential handling, explicitly forbidding the exposure of secrets in logs, prompts, browser research, or client-side code (SKILL.md).
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 8, 2026, 02:26 AM
Security Audit — agent-trust-hub — squad-frontend