skills/poteto/noodle/frontend-design/Gen Agent Trust Hub

frontend-design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted user-supplied requirements to generate functional web code without defined input boundaries.
  • Ingestion points: User-provided frontend requirements, purpose, audience context, and technical constraints (SKILL.md).
  • Boundary markers: The instructions do not provide explicit delimiters or warnings to treat user context as potentially untrusted.
  • Capability inventory: The skill directs the agent to generate production-grade, functional code including HTML, CSS, JavaScript, React, and Vue components.
  • Sanitization: There is no mention of sanitizing or validating user input before it is used to influence code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:26 PM