weapp-tailwindcss-custom-build

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses natural instructional language focused on build system integration. No attempts to override safety filters, bypass instructions, or extract system prompts were detected.- [DATA_EXFILTRATION]: The instructions focus on in-memory transformations of code. No network-based exfiltration patterns, hardcoded credentials, or access to sensitive environment or configuration files were found.- [REMOTE_CODE_EXECUTION]: The skill references the local integration of the weapp-tailwindcss/core module within standard build toolchains. It does not include remote script downloads, piped shell executions, or unverifiable third-party dependencies from untrusted sources.- [OBFUSCATION]: All content and code snippets are provided in plain, readable text. No Base64 encoding, hex-escapes, zero-width characters, or other techniques to hide malicious intent were identified.- [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external code (CSS, JS, templates) through its core API, it is intended for use within controlled build environments. The documentation highlights the use of validated class sets from Tailwind generation, which serves as a natural boundary against untrusted string ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 06:25 AM
Security Audit — agent-trust-hub — weapp-tailwindcss-custom-build