frontend-workflow
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Automated execution of local scripts. The skill configures
PostToolUsehooks to run bash scripts located in~/.claude/hooks/(specificallyts-check.sh,auto-prettier.sh, andconsole-log-check.sh) after file modifications. This creates an automated execution path triggered by the agent's code editing activities. - [EXTERNAL_DOWNLOADS]: Data ingestion from external MCP tools. The workflow mandates calling various MCP tools to fetch documentation and UI patterns (e.g.,
fetch_tailwind_docs,get_ecommerce_ui_pattern). The agent is instructed to follow this external content strictly during implementation. - [PROMPT_INJECTION]: Indirect prompt injection surface via external data ingestion. The skill ingests documentation from external sources and uses it to drive code generation, which presents a surface for indirect instruction injection. * Ingestion points: MCP tool outputs from documentation-fetching functions defined in
SKILL.md. * Boundary markers: Not present; the skill lacks delimiters or warnings to ignore instructions embedded in the fetched documentation. * Capability inventory: File system modification via theEdittool and shell command execution via defined hooks. * Sanitization: No verification or sanitization of the content returned by the MCP tools is mentioned.
Audit Metadata