css-first
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a maintenance script,
scripts/update_baseline.py, which fetches feature compatibility data from the official Web Platform Status API (api.webstatus.dev). This is a well-known service operated by the W3C WebDX Community Group, used to provide accurate Baseline status for web features. - [PROMPT_INJECTION]: The skill instructions in
SKILL.mdand related rules files guide the agent to prioritize CSS solutions over JavaScript. These instructions are consistent with the skill's primary purpose and do not attempt to override agent safety constraints or behavioral boundaries. - [DATA_EXPOSURE_&_EXFILTRATION]: The skill includes a security-conscious reference file (
references/live-mdn-fetch.md) that explicitly instructs the agent to treat all fetched external data as untrusted information and never as instructions, significantly reducing the risk of indirect prompt injection or data-driven attacks.
Audit Metadata