vercel-geist-design-system

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it is designed to ingest and analyze local project files (e.g., routes, configurations, and entrypoints) to map the UI, while maintaining the capability to execute shell commands and browser automation.
  • Ingestion points: Local project files such as framework route directories (/app, /pages), configuration files (next.config.js, sitemap), and main application entrypoints.
  • Boundary markers: The skill does not define explicit markers for ingested content but establishes a rigid "Foundation Gate" and operating loop to govern the agent's workflow.
  • Capability inventory: Execution of subprocesses for local development commands and browser-based verification tools (screenshots and interaction audits).
  • Sanitization: There is no mention of sanitizing or escaping the content of project files before analysis.
  • [COMMAND_EXECUTION]: The skill directs the agent to identify and run local project development commands (e.g., npm run dev) and use browser automation frameworks like Playwright to perform visual audits and verify interaction behavior.
  • [EXTERNAL_DOWNLOADS]: The skill references companion utilities that may attempt to install external dependencies (such as screenshot tooling), but it includes a security policy requiring explicit user consent before any installers are executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 03:48 PM
Security Audit — agent-trust-hub — vercel-geist-design-system