next-variant
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates within its stated functional scope, providing a structured framework for analyzing design tokens and generating React/HTML components based on predefined style skills.
- [EXTERNAL_DOWNLOADS]: The skill uses browser/fetch tools to retrieve source data (HTML and linked CSS) from user-provided URLs. This is a core functionality for the 'Website Style Reverse Extraction' feature and is used to identify visual attributes like colors, fonts, and layout structures.
- [PROMPT_INJECTION]: By processing data from external websites, the skill possesses an indirect prompt injection surface. However, the logic is constrained to extracting technical design tokens (e.g., CSS variables, font families), which significantly limits the potential for executing instructions embedded in malicious third-party content.
Audit Metadata