tailwind-design-system
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on user-provided design requirements to generate component code and configurations, which presents an attack surface for indirect prompt injection if those requirements are sourced from untrusted external data.
- Ingestion points: User specifications for components, design tokens, and UI behavior.
- Boundary markers: The provided files do not include explicit delimiter-based safety instructions to isolate user data.
- Capability inventory: The skill is designed to generate React components, Tailwind CSS configurations, and global stylesheets.
- Sanitization: Relies on the underlying agent safety guardrails for code generation tasks.
- [EXTERNAL_DOWNLOADS]: The implementation playbook references and provides configuration for several standard frontend libraries.
- Evidence: The skill configuration and implementation guide reference tailwindcss-animate, class-variance-authority, Radix UI primitives, Lucide React, and Zod. These are recognized as well-known and safe industry libraries.
Audit Metadata