frontend-design
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill automates the installation of standard web development libraries from the npm registry using
pnpm. These include well-known packages like Vite, Tailwind CSS, Radix UI, and Parcel, which are essential for its scaffolding and bundling functionality. - [DATA_EXPOSURE]: The image generation tool (
scripts/generate_images.py) is designed to load an API key from a.env.localfile by searching parent directories. This is a common development practice for managing local environment secrets and does not indicate unauthorized data access. - [COMMAND_EXECUTION]: The skill utilizes local shell scripts (
scripts/init-artifact.shandscripts/bundle-artifact.sh) and Python utilities to manage project files and run audits. These actions are performed within the local project context using standard command-line tools. - [PROMPT_INJECTION]: The skill contains instructional constraints intended to guide the agent's design style (such as avoiding specific overused UI patterns). These are legitimate behavioral guidelines for the AI and do not represent a security risk.
Audit Metadata