webflow-dev

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The instructions focus on legitimate Webflow development workflows, emphasizing the reuse of existing site systems and design parity. It includes multiple verification steps to ensure quality and prevent unintended changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external design sources (Figma and Paper MCP tools). While this represents a data ingestion surface, the skill implements strict boundary markers and verification steps, such as confirming artboards and inventorying existing systems before execution, which mitigates injection risks. As this is core to the skill's primary purpose, it does not escalate the security verdict.
  • [REMOTE_CODE_EXECUTION]: The skill references the use of Model Context Protocol (MCP) tools for Figma and Paper. These are standard platform extensions for design inspection and do not involve unauthorized remote script execution or unverifiable dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 04:13 PM
Security Audit — agent-trust-hub — webflow-dev