frontend-design
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified.
- Ingestion points: Analysis scripts (analyze-styles.ts, analyze-accessibility.ts, extract-tokens.ts) ingest content from external CSS, HTML, and component files.
- Boundary markers: Absent. The scripts do not use delimiters or instructions to ignore potential instructions embedded in processed files.
- Capability inventory: The skill requests and uses file-writing capabilities via Deno.writeTextFile in all generation scripts (generate-component.ts, generate-palette.ts, etc.).
- Sanitization: The generate-component.ts script does not sanitize the component name input, which is directly used to construct output file paths. A maliciously crafted name (e.g., using path traversal characters) could allow writing files outside the intended output directory.
- [PROMPT_INJECTION]: Metadata discrepancy detected. The author field in the SKILL.md frontmatter ('agent-skills') does not align with the provided author context ('ibossyNr1'), which may indicate a deceptive or misleading metadata configuration.
Audit Metadata