tailwind-design-system

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on user-provided design requirements to generate component code and configurations, which presents an attack surface for indirect prompt injection if those requirements are sourced from untrusted external data.
  • Ingestion points: User specifications for components, design tokens, and UI behavior.
  • Boundary markers: The provided files do not include explicit delimiter-based safety instructions to isolate user data.
  • Capability inventory: The skill is designed to generate React components, Tailwind CSS configurations, and global stylesheets.
  • Sanitization: Relies on the underlying agent safety guardrails for code generation tasks.
  • [EXTERNAL_DOWNLOADS]: The implementation playbook references and provides configuration for several standard frontend libraries.
  • Evidence: The skill configuration and implementation guide reference tailwindcss-animate, class-variance-authority, Radix UI primitives, Lucide React, and Zod. These are recognized as well-known and safe industry libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:51 PM
Security Audit — agent-trust-hub — tailwind-design-system