frontend-design

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external design references, screenshots, and inspiration links provided by users (SKILL.md, reference-research.md). This creates a vulnerability surface where instructions hidden within these external materials could attempt to override the agent's behavior.\n
  • Ingestion points: User-supplied target references and inspiration material documented in SKILL.md and reference-research.md.\n
  • Boundary markers: The skill defines a clear hierarchy of evidence, prioritizing the user's specific request and the existing product implementation over external inspiration (SKILL.md).\n
  • Capability inventory: The skill leverages standard agent capabilities for file modification and UI review. No dangerous subprocess calls, network exfiltration scripts, or privilege escalation patterns were identified in the analyzed files.\n
  • Sanitization: The skill employs an 'Interchangeability Gate' (SKILL.md) and a 'Quality Gate' (quality-gate.md) to validate design choices against functional requirements, accessibility standards, and product-specific contracts, reducing the likelihood of malicious influence from external design trends.\n- [EXTERNAL_DOWNLOADS]: The skill references several external documentation resources and design systems from well-known organizations including W3C, Mozilla, GitHub, and Vercel (source-notes.md). These are provided as design authority references for the agent to consult during implementation review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:17 PM
Security Audit — agent-trust-hub — frontend-design