taste-design-taste-frontend

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references resources and documentation from several well-known services and trusted organizations. It fetches icons from Cloudflare and Simple Icons, placeholder photography from Picsum, and official documentation from Apple, Microsoft, IBM, and Shopify. These references are used for legitimate design purposes and target established domains.
  • [COMMAND_EXECUTION]: The skill provides standard installation instructions for numerous official UI frameworks and libraries. It includes commands for 'npm install' and 'yarn add' for packages from verified organizations like Google, Microsoft, IBM, Atlassian, and GitHub, as well as initialization commands for the shadcn/ui library. All commands target official package registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on user-provided design briefs to infer the appropriate aesthetic direction and generate code. This creates a surface where external instructions could influence the agent's behavior. The skill mitigates this by instructing the agent to perform a 'Brief Inference' step and a 'Copy Self-Audit' before finalizing output, though it lacks formal boundary markers for the interpolated content.
  • Ingestion points: User-provided design brief (Section 0).
  • Boundary markers: Absent.
  • Capability inventory: Generates React/Next.js code and executes package manager commands (npm/yarn).
  • Sanitization: Includes a manual self-audit check for generated strings (Section 4.9).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 07:10 AM
Security Audit — agent-trust-hub — taste-design-taste-frontend