code-frontend-design
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on improving UI/UX design and adheres to best practices such as accessibility and semantic HTML. No malicious patterns, obfuscation, or unauthorized network activity were identified.
- [DATA_EXPOSURE]: The skill instructions include reading project-specific configuration files such as
design-brief.mdandstack-confirmed.md. This behavior is consistent with its primary function of aligning UI implementation with existing project standards and does not involve access to sensitive system files, environment variables, or credentials. - [INDIRECT_PROMPT_INJECTION]: The skill acts on external data sources to inform design decisions, creating a potential surface for indirect prompt injection.
- Ingestion points: Reads
docs/context/design-brief.md,docs/context/stack-confirmed.md, and existing UI patterns from the codebase. - Boundary markers: No specific boundary markers or "ignore embedded instructions" warnings for ingested data were observed.
- Capability inventory: The skill is capable of reading local files and generating/writing UI code. It does not possess network or high-privilege command execution capabilities.
- Sanitization: No explicit sanitization or validation of the ingested documentation was found.
- This represents a low-risk surface because the skill's capabilities are restricted to UI-related tasks and code generation without execution of the generated content in a high-privilege context.
Audit Metadata