skills/emmraan/agent-skills/webflow/Gen Agent Trust Hub

webflow

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external Figma design data which constitutes a potential indirect prompt injection surface. However, the instructions mitigate this by requiring explicit user confirmation (e.g., requiring the user to type 'add' or 'update') before the agent performs any mutations or script injections on the target Webflow site.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of standard development dependencies and official Webflow packages such as @webflow/webflow-cli, @webflow/react, and @webflow/data-types. These downloads originate from the official NPM registry and are necessary for the skill's primary functionality.
  • [DATA_EXFILTRATION]: Instructions regarding the WEBFLOW_WORKSPACE_API_TOKEN emphasize secure handling, such as using environment variables and ensuring sensitive files like .env are excluded from version control via .gitignore. No unauthorized data transmission to non-Webflow domains was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 12:31 PM
Security Audit — agent-trust-hub — webflow