web-design-guidelines
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches configuration and review instructions from the Vercel Labs official GitHub repository to perform audits.
- [COMMAND_EXECUTION]: Reads local UI code files as specified by the user to conduct the requested design check.
- [PROMPT_INJECTION]: The skill ingests instructions from a remote URL to define its auditing logic, representing an indirect prompt injection surface.
- Ingestion points: Remote content fetched from the Vercel Labs repository via SKILL.md.
- Boundary markers: Absent for the fetched remote guidelines.
- Capability inventory: Read access to local project files.
- Sanitization: No explicit validation or filtering of the fetched content is specified.
Audit Metadata