tailwind-4-docs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a synchronization script,
scripts/sync_tailwind_docs.py, to fetch documentation from the official Tailwind CSS GitHub repository (https://github.com/tailwindlabs/tailwindcss.com). This is a legitimate operation to populate the agent's reference library with official content from a well-known source. - [COMMAND_EXECUTION]: The
sync_tailwind_docs.pyscript executesgitcommands (clone, fetch, checkout, reset) via Python'ssubprocess.runto manage the local documentation snapshot. These commands are used for data synchronization and are limited to the specific documentation repository. - [INDIRECT_PROMPT_INJECTION]: The skill ingests MDX documentation files from an external repository, which creates an indirect prompt injection surface.
- Ingestion points: External content is loaded from
references/docs/when the agent answers user questions about Tailwind CSS. - Boundary markers: The
SKILL.mdfile contains instructions for the agent to treat MDX metadata and JSX tags as metadata and guidance text, rather than instructions to follow. - Capability inventory: The skill includes a Python script that can perform file system operations (
shutil) and executegitviasubprocess. - Sanitization: No specific sanitization is performed on the downloaded MDX files, but the agent is guided on how to interpret the content as reference material.
Audit Metadata