create-component

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions are entirely focused on standard frontend development patterns. The workflow focuses on code quality, composition, and styling consistency with tailwind-variants. There is no evidence of prompt injection, data exfiltration, or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent reads local project files like AGENTS.md and existing components to inform design choices. While this constitutes an ingestion surface for untrusted data if the project files are compromised, the risk is minimal and inherent to the development task. Ingestion points: AGENTS.md, package exports, and local source code files in SKILL.md. Boundary markers: Absent. Capability inventory: File creation/refactoring and execution of type/lint checks in SKILL.md. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 04:21 PM
Security Audit — agent-trust-hub — create-component