frontend-security
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructional content and code examples for implementing frontend security best practices. All external references target well-known, trusted services or repositories such as Snyk, npm, and official framework documentation. No evidence of malicious behavior, obfuscation, or data exfiltration was found.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates auditing of user-provided frontend code, which creates a surface where instructions embedded in processed data could attempt to influence agent behavior (ingestion point). The skill lacks explicit boundary markers or sanitization for this untrusted data. Its capabilities are focused on generating text-based security guidance and header configurations (capability inventory). This attack surface is inherent to its primary purpose as a security auditor and is not considered a malicious finding.
Audit Metadata