gpt-taste
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [SAFE]: The skill focuses on defining aesthetic and layout constraints for AI-generated React code, ensuring visual quality and variety through design principles.
- [EXTERNAL_DOWNLOADS]: References to picsum.photos for placeholder images and libraries such as GSAP and Phosphor Icons are safe and involve well-known, legitimate services.
- [PROMPT_INJECTION]: The use of imperative language like 'CORE DIRECTIVE' and 'FORBIDDEN' is employed for style enforcement and defining the agent persona rather than attempting to subvert platform safety measures.
- [REMOTE_CODE_EXECUTION]: Instructions to 'simulate a Python script execution' are intended for internal model reasoning to generate deterministic variety and do not represent a technical shell or system execution risk.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface: 1. Ingestion points: User prompts (SKILL.md); 2. Boundary markers: Absent; 3. Capability inventory: Generates React UI code with external asset links and GSAP animations (SKILL.md); 4. Sanitization: Absent.
Audit Metadata