frontend-design-guidelines
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes bash scripts for session tracking and telemetry. These scripts interact with the
~/.superstackdirectory in the user home folder. - [DATA_EXFILTRATION]: Telemetry metadata is transmitted to an external service using
curl. This behavior is transparent and includes a user consent prompt. - [PROMPT_INJECTION]: The skill reads instructions from a project-level
brand.mdfile, which is a surface for indirect prompt injection. Ingestion points: Project rootbrand.md. Boundary markers: None. Capability inventory: Shell execution, filesystem access, and component generation. Sanitization: None.
Audit Metadata