weapp-tailwindcss-custom-build
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses natural instructional language focused on build system integration. No attempts to override safety filters, bypass instructions, or extract system prompts were detected.- [DATA_EXFILTRATION]: The instructions focus on in-memory transformations of code. No network-based exfiltration patterns, hardcoded credentials, or access to sensitive environment or configuration files were found.- [REMOTE_CODE_EXECUTION]: The skill references the local integration of the
weapp-tailwindcss/coremodule within standard build toolchains. It does not include remote script downloads, piped shell executions, or unverifiable third-party dependencies from untrusted sources.- [OBFUSCATION]: All content and code snippets are provided in plain, readable text. No Base64 encoding, hex-escapes, zero-width characters, or other techniques to hide malicious intent were identified.- [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external code (CSS, JS, templates) through its core API, it is intended for use within controlled build environments. The documentation highlights the use of validated class sets from Tailwind generation, which serves as a natural boundary against untrusted string ingestion.
Audit Metadata