web-design-guidelines
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill fetches design guidelines and instructions from a trusted repository owned by Vercel Labs. This is a legitimate functional requirement for design auditing.
- [PROMPT_INJECTION]: The skill architecture creates an indirect prompt injection surface by ingesting instructions from a remote source that influence the agent's behavior.
- Ingestion points: Remote Markdown file at
https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.md. - Boundary markers: None specified in the instructions.
- Capability inventory: Reads local files to perform audits.
- Sanitization: No content sanitization or validation of the remote guidelines is performed before processing.
Audit Metadata