frontend-workflow

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Automated execution of local scripts. The skill configures PostToolUse hooks to run bash scripts located in ~/.claude/hooks/ (specifically ts-check.sh, auto-prettier.sh, and console-log-check.sh) after file modifications. This creates an automated execution path triggered by the agent's code editing activities.
  • [EXTERNAL_DOWNLOADS]: Data ingestion from external MCP tools. The workflow mandates calling various MCP tools to fetch documentation and UI patterns (e.g., fetch_tailwind_docs, get_ecommerce_ui_pattern). The agent is instructed to follow this external content strictly during implementation.
  • [PROMPT_INJECTION]: Indirect prompt injection surface via external data ingestion. The skill ingests documentation from external sources and uses it to drive code generation, which presents a surface for indirect instruction injection. * Ingestion points: MCP tool outputs from documentation-fetching functions defined in SKILL.md. * Boundary markers: Not present; the skill lacks delimiters or warnings to ignore instructions embedded in the fetched documentation. * Capability inventory: File system modification via the Edit tool and shell command execution via defined hooks. * Sanitization: No verification or sanitization of the content returned by the MCP tools is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 02:13 AM