tailwindcss

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to execute shell commands such as npm run test, npx tailwindcss, and npm run build as part of the development and verification workflow. These commands are standard for JavaScript-based frontend development and do not involve untrusted remote sources or user-supplied input injection.
  • [DYNAMIC_EXECUTION]: The skill includes configuration files (tailwind.config.js) and a custom plugin (plugins/holographic.js) which contain JavaScript logic executed during the CSS build process. This is the standard mechanism for Tailwind CSS extensibility and is used here for theme extension and utility generation without unsafe dynamic evaluations.
  • [INDIRECT_PROMPT_INJECTION]: The provided Vue components define an attack surface by accepting props (e.g., title, label) that ingest external data.
  • Ingestion points: props in HUDPanel.vue, StatusIndicator.vue, and Button components in SKILL.md.
  • Boundary markers: None present in the component templates to separate instructions from data.
  • Capability inventory: Shell commands npm run test, npx tailwindcss, and npm run build mentioned in SKILL.md for project verification.
  • Sanitization: Vue.js default interpolation {{ }} is used for data binding, which provides automatic HTML escaping to prevent cross-site scripting (XSS).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:55 PM
Security Audit — agent-trust-hub — tailwindcss