frontend-design-deslop

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of established external design resources, including CSS frameworks from CDNs like unpkg.com (Open Props), typography from Google Fonts and Fontshare, and various well-known component libraries (shadcn/ui, Magic UI, Aceternity). These are standard industry tools and are documented as inspiration or implementation helpers rather than unverified dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it is designed to ingest external content via the WebFetch tool for design inspiration and to read existing project documentation like DESIGN.md. While malicious instructions could theoretically be embedded in these external sources to influence the agent's design choices, the skill operates within standard agent constraints and focuses on aesthetic and structural UI guidance.
  • Ingestion points: WebFetch for web searching design references and Read for existing DESIGN.md files at the project root.
  • Boundary markers: The skill uses a structured 'Phase' system (Discovery, Strategy, Application, Audit) which acts as a logical boundary for how information is processed, though it does not explicitly define character-level delimiters for external text.
  • Capability inventory: The skill is authorized to use Read, Edit, Write, Glob, Grep, Agent, AskUserQuestion, WebSearch, and WebFetch. These tools are necessary for its primary purpose of designing and documenting project UI.
  • Sanitization: No explicit sanitization of fetched web content or local markdown files is mentioned; however, the data is primarily used to inform aesthetic decisions and generate CSS/Markdown tokens.
  • [SAFE]: The skill is authored by 'samber' and references official vendor resources on GitHub (github.com/samber/cc-skills). All identified external connections are to well-known technology services and design platforms, meeting the criteria for safe external references.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 08:01 PM
Security Audit — agent-trust-hub — frontend-design-deslop