frontend-design
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external design references, screenshots, and inspiration links provided by users (SKILL.md, reference-research.md). This creates a vulnerability surface where instructions hidden within these external materials could attempt to override the agent's behavior.\n
- Ingestion points: User-supplied target references and inspiration material documented in SKILL.md and reference-research.md.\n
- Boundary markers: The skill defines a clear hierarchy of evidence, prioritizing the user's specific request and the existing product implementation over external inspiration (SKILL.md).\n
- Capability inventory: The skill leverages standard agent capabilities for file modification and UI review. No dangerous subprocess calls, network exfiltration scripts, or privilege escalation patterns were identified in the analyzed files.\n
- Sanitization: The skill employs an 'Interchangeability Gate' (SKILL.md) and a 'Quality Gate' (quality-gate.md) to validate design choices against functional requirements, accessibility standards, and product-specific contracts, reducing the likelihood of malicious influence from external design trends.\n- [EXTERNAL_DOWNLOADS]: The skill references several external documentation resources and design systems from well-known organizations including W3C, Mozilla, GitHub, and Vercel (source-notes.md). These are provided as design authority references for the agent to consult during implementation review.
Audit Metadata