web-design-guidelines
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches design guidelines from a Vercel Labs public repository.
- Evidence:
https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.mdreferenced in SKILL.md. - [PROMPT_INJECTION]: The skill processes untrusted user source code, creating a surface for potential indirect prompt injection.
- Ingestion points: User-supplied source code files in SKILL.md.
- Boundary markers: None specified in the instructions.
- Capability inventory: Reading local files and fetching external web content via WebFetch in SKILL.md.
- Sanitization: No sanitization of ingested content is described.
Audit Metadata