skills/fe-dudu/skills/oh-my-frontend/Gen Agent Trust Hub

oh-my-frontend

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a purely instructional and organizational framework for agent-based frontend development. It does not contain executable code, hidden payloads, or suspicious network activities.
  • [INDIRECT_PROMPT_INJECTION]: The skill's architecture involves processing external project documentation and user input to drive agent actions. While this introduces an indirect prompt injection surface, it is addressed through defensive design. 1. Ingestion points: The skill reads from a project's '/docs' directory and processes user answers during clarifying interviews. 2. Boundary markers: Instructions mandate the use of specific Markdown templates, tables, and Mermaid diagrams to structure and isolate data. 3. Capability inventory: The skill coordinates implementation tasks that may access the local file system and execute build/test tools via external referenced skills like frontend-engineering. 4. Sanitization: The 'security-and-privacy.md' reference provides explicit requirements for validating external content, rendered HTML, and redirect targets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:23 PM
Security Audit — agent-trust-hub — oh-my-frontend