frontend-ui-ux-wizard
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of developer tools and packages from well-known and official sources, including Microsoft's Playwright MCP, the 21st.dev CLI, and official deployment tools from Vercel, Netlify, and Cloudflare.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by fetching external framework documentation and UI components. To mitigate risk, it includes specific defensive instructions (Category 8 surface) in the 'Trust boundaries' section, advising the agent to treat fetched content as reference material only and to avoid executing embedded instructions.
- [COMMAND_EXECUTION]: Shell commands are used for standard development workflows, such as building projects (
npm run build), version control (git push), and deployment. These operations are consistent with the skill's primary function as a frontend development tool. - [OBFUSCATION]: The
Lanyardcomponent includes a Base64-encoded string representing a 1x1 transparent PNG pixel. This is a common web development practice used for placeholders and does not contain malicious code or hidden URLs.
Audit Metadata