frontend-design
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the generation of functional frontend code (React, CSS, and animations) based on user-provided project blueprints. This creates a potential attack surface where malicious instructions embedded in a user's UI request could be translated into the generated code or artifact.
- Ingestion points: User-supplied project descriptions, aesthetic preferences, and UI requirements (SKILL.md).
- Boundary markers: None present; the instructions do not specify delimiters for user input or warnings to ignore embedded instructions in data.
- Capability inventory: Generation and execution of HTML, CSS, and JavaScript (including Framer Motion and GSAP animations) within the agent's artifact environment.
- Sanitization: The skill does not provide explicit mechanisms for sanitizing or escaping user input before incorporating it into the generated code templates.
Audit Metadata