microsoft-frontend-design-review

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from external sources to influence its code generation and review logic.\n
  • Ingestion points: The workflow in SKILL.md explicitly gathers context from external sources including screenshots, source code, and Figma references.\n
  • Boundary markers: The skill lacks defined delimiters or clear instructions to isolate external data from the primary instructions, which may lead to the agent following instructions embedded within the reviewed data.\n
  • Capability inventory: The skill is capable of generating and delivering functional frontend code (HTML/CSS/JS), which could be manipulated by an attacker to include malicious scripts or payloads.\n
  • Sanitization: There are no requirements for the agent to sanitize, validate, or escape the external content before using it to generate implementation rationales or working code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:00 PM
Security Audit — agent-trust-hub — microsoft-frontend-design-review