frontend-security-coder
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No malicious override instructions, safety filter bypasses, or 'DAN' style patterns were detected. The instructions focus on defining the agent's role as a security-focused frontend developer.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file path access (e.g., .ssh, .env), or unauthorized network requests were found. The skill mentions token storage only in the context of teaching secure practices to the user.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote script downloads or unauthorized package installations. All tool usage is within standard development scopes.
- [OBFUSCATION]: No Base64 encoding, zero-width characters, homoglyphs, or hidden URL patterns were identified in the provided content.
- [INDIRECT_PROMPT_INJECTION]: The skill represents a low-risk profile as it primarily generates text-based security guidance. While it handles user-provided code, it lacks capabilities like file system writes or network egress that would enable exploitation via untrusted data ingestion.
- [COMMAND_EXECUTION]: No dangerous shell command execution, privilege escalation (sudo), or persistence mechanisms were detected. The skill uses standard markdown and instructional prose.
Audit Metadata