frontend-security-coder-v3

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an inherent attack surface for indirect prompt injection as it is designed to ingest and analyze untrusted data in the form of frontend code and user-provided security tasks.
  • Ingestion points: Untrusted content enters the agent's context through user tasks and code snippets processed during the workflow (SKILL.md).
  • Boundary markers: Absent; the instructions do not include specific delimiters or warnings to treat processed data as untrusted.
  • Capability inventory: The skill is configured to utilize tools like claude-code, cursor, and gemini-cli, which have capabilities for file system interaction and command execution.
  • Sanitization: Absent; the skill does not specify any validation or sanitization procedures for the external content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 11:38 AM
Security Audit — agent-trust-hub — frontend-security-coder-v3