css-order

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for optimizing web performance by ordering CSS and JS correctly. No malicious instructions, obfuscation, or persistence mechanisms were detected.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The reference documentation includes code examples that utilize well-known development libraries such as Puppeteer, Cheerio, Webpack, and Vite for performance analysis and build-time optimization. These are used for their intended development purposes and originate from reputable ecosystems.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it involves the agent reading and reviewing external CSS and HTML files. Ingestion points: Reading stylesheets and component styles (SKILL.md). Boundary markers: Absent. Capability inventory: File reading (fs) and browser automation (puppeteer) are described in reference scripts (references/rule.md). Sanitization: Absent. The risk is assessed as safe due to the specific and restricted nature of the analysis task.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:30 AM
Security Audit — agent-trust-hub — css-order