planning-frontend-design-orchestrator

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local Node.js scripts (validate-concepts-playwright.mjs and validate-design-uniqueness.mjs) to automate the rendering of generated UI views and perform structural comparison across passes to ensure visual quality and variety.
  • [EXTERNAL_DOWNLOADS]: Facilitates the optional downloading of media assets and the inclusion of verified CDN libraries to enhance the generated frontend designs, based on centralized catalogs provided in the skill references.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads from multiple project files including product-context.md, style-config.json, and catalogs for libraries, assets, and inspiration to build creative briefs for sub-agents.
  • Boundary markers: Does not employ specific delimiters when passing external content or project metadata to the sub-agent's creative brief.
  • Capability inventory: The skill dispatches Task agents to generate code, writes those files to disk, and executes validation commands via Node.js.
  • Sanitization: Design content and configuration data are processed as part of the creative workflow without explicit mention of sanitization steps in the orchestration logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 01:44 PM
Security Audit — agent-trust-hub — planning-frontend-design-orchestrator