tailwind-4
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains standard instructional language and does not attempt to override agent safety filters or system prompts.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network exfiltration patterns were identified. The code examples use local style properties and semantic identifiers.
- [OBFUSCATION]: The content is clear and readable. No Base64, zero-width characters, or hidden Unicode tags were found.
- [REMOTE_CODE_EXECUTION]: While the skill references well-known utility libraries (clsx, tailwind-merge, class-variance-authority), it does not include commands to download or execute code from untrusted remote sources.
- [PRIVILEGE_ESCALATION]: The skill does not contain any commands related to administrative access, permission changes, or service installations.
- [PERSISTENCE_MECHANISMS]: No patterns targeting shell profiles, cron jobs, or startup directories were found.
- [METADATA_POISONING]: The metadata fields (name, description, author) accurately reflect the content of the skill and do not contain deceptive instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill focuses on static code patterns and does not establish a surface for processing untrusted external data that could lead to injection.
- [TIME_DELAYED_OR_CONDITIONAL_ATTACKS]: There are no time-based triggers or environmental checks gating suspicious operations.
- [DYNAMIC_EXECUTION]: The dynamic styling examples correctly use React style props and CSS custom properties for runtime calculations, which are standard frontend practices and present no security risk.
- [DYNAMIC_CONTEXT_INJECTION]: No shell command placeholders (!
command) were found in the documentation.
Audit Metadata