unocss
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a technical reference for UnoCSS, providing configuration templates and usage examples for its core features, presets, and transformers.\n- [EXTERNAL_DOWNLOADS]: The skill references several well-known and reputable external services for assets, such as Google Fonts and Iconify (via the esm.sh CDN). These are standard integrations for the UnoCSS ecosystem and are documented for their intended use in web development.\n- [COMMAND_EXECUTION]: The integration guides for Vite and Nuxt provide standard developer commands for installing the
unocssand@unocss/nuxtpackages via thepnpmpackage manager. No suspicious, privileged, or hidden command execution patterns were found.\n- [PROMPT_INJECTION]: The skill describes how the agent can extract CSS utilities from various sources, including the filesystem and inline text fetched from remote URLs. While this defines a data ingestion surface for potential indirect prompt injection, the skill's capabilities are strictly focused on CSS generation, and the documentation follows standard usage patterns without requesting dangerous system permissions or bypassing safety guardrails.
Audit Metadata