tailwindcss

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The instructions use emphasized directives like 'CRITICAL' and 'MUST' to guide the agent to disregard its internal training data in favor of live documentation. While this is intended to ensure technical accuracy for the v4 rewrite, it uses behavioral override patterns.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch live documentation from tailwindcss.com. This introduces an indirect prompt injection surface where the agent processes external data.
  • Ingestion points: Live documentation fetched from tailwindcss.com as specified in SKILL.md.
  • Boundary markers: None provided to delimit the fetched content from the agent's instructions.
  • Capability inventory: The agent is expected to generate code and configure projects based on the fetched data.
  • Sanitization: No specific sanitization or verification of the external content is performed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 11:35 AM