spencer-approved-frontends

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides documentation for initializing new projects using standard development tools like npm, npx, and vite. These commands are routine for frontend scaffolding and are presented as instructions for the developer to follow during project setup.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, well-known Node.js packages (tailwindcss, postcss, autoprefixer) from the official npm registry for styling purposes. These are necessary for the skill's primary function and come from a trusted service.
  • [DATA_EXPOSURE]: The skill instructs the agent to reference existing local repositories in ~/Repos/ (specifically due-diligence and security-review) to maintain visual consistency. This is a local read operation within the context of design reference and does not involve exfiltration.
  • [DYNAMIC_EXECUTION]: The provided React components and utilities use standard React state management and effects. The textarea-autoresize pattern uses standard DOM manipulation (scrollHeight) which is safe and common practice for that specific functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:06 PM
Security Audit — agent-trust-hub — spencer-approved-frontends