tailwindcss
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to execute shell commands such as
npm run test,npx tailwindcss, andnpm run buildas part of the development and verification workflow. These commands are standard for JavaScript-based frontend development and do not involve untrusted remote sources or user-supplied input injection. - [DYNAMIC_EXECUTION]: The skill includes configuration files (
tailwind.config.js) and a custom plugin (plugins/holographic.js) which contain JavaScript logic executed during the CSS build process. This is the standard mechanism for Tailwind CSS extensibility and is used here for theme extension and utility generation without unsafe dynamic evaluations. - [INDIRECT_PROMPT_INJECTION]: The provided Vue components define an attack surface by accepting props (e.g.,
title,label) that ingest external data. - Ingestion points:
propsinHUDPanel.vue,StatusIndicator.vue, andButtoncomponents inSKILL.md. - Boundary markers: None present in the component templates to separate instructions from data.
- Capability inventory: Shell commands
npm run test,npx tailwindcss, andnpm run buildmentioned inSKILL.mdfor project verification. - Sanitization: Vue.js default interpolation
{{ }}is used for data binding, which provides automatic HTML escaping to prevent cross-site scripting (XSS).
Audit Metadata