frontend-design-guidelines

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes bash scripts for session tracking and telemetry. These scripts interact with the ~/.superstack directory in the user home folder.
  • [DATA_EXFILTRATION]: Telemetry metadata is transmitted to an external service using curl. This behavior is transparent and includes a user consent prompt.
  • [PROMPT_INJECTION]: The skill reads instructions from a project-level brand.md file, which is a surface for indirect prompt injection. Ingestion points: Project root brand.md. Boundary markers: None. Capability inventory: Shell execution, filesystem access, and component generation. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:05 AM
Security Audit — agent-trust-hub — frontend-design-guidelines