security-frontend-browser-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidelines and best practices for performing security reviews of frontend code and pull requests. It focuses on well-known vulnerability classes such as Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and insecure browser storage.
- [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, or unauthorized command execution, were identified in the instructions or reference files.
- [SAFE]: The reference files contain legitimate security knowledge intended to guide an AI agent in identifying potential risks in code changes. The Polish-language introduction in the reference file is benign and serves as internal documentation for the skill's usage.
- [INDIRECT_PROMPT_INJECTION]: As a code review tool, the skill naturally ingests untrusted data (pull request diffs). While this presents a surface for indirect prompt injection, the skill itself does not request dangerous tools or capabilities that could be exploited to compromise the host system. The risk is considered low and inherent to the task of code analysis.
Audit Metadata