design-taste-frontend

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads official frontend libraries and design systems from trusted organizations, including Microsoft (Fluent UI), Google (Material Web), IBM (Carbon), GitHub (Primer), Atlassian (Atlaskit), and Vercel (Geist via Radix/Tailwind).\n- [COMMAND_EXECUTION]: The skill uses standard package manager commands (npm install, npx shadcn) to set up and configure the development environment as part of its normal workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user design briefs as its primary input, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Section 0 ("Read these signals first") describes processing user-provided briefs, vibration words, and reference URLs.\n
  • Boundary markers: The mandatory "Design Read" declaration (Section 0.B) acts as a verification step, forcing the agent to summarize intent before generating code.\n
  • Capability inventory: The skill is scoped to React, Next.js, and CSS generation; it does not possess high-risk capabilities like arbitrary shell access, sensitive file writes, or network exfiltration tools.\n
  • Sanitization: Boundary markers are used to align intent, but formal technical sanitization of the natural language input is not described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — design-taste-frontend