naming-conventions

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation reference for CSS best practices. It does not contain any executable scripts, binary files, or automated commands that could compromise the host system.
  • [EXTERNAL_DOWNLOADS]: The skill references external URLs for documentation purposes (e.g., frontendchecklist.io, MDN, web.dev). These are well-known and trusted web development resources and do not involve the download of executable code or scripts.
  • [DATA_EXFILTRATION]: No patterns for accessing sensitive files (like .env, .ssh, or cloud credentials) or exfiltrating data via network requests were found.
  • [PROMPT_INJECTION]: The instructions are focused on code review and do not attempt to override system prompts or bypass AI safety guardrails.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external CSS files as part of its code review function. While this creates a theoretical surface for indirect injection via malicious class names, the skill does not grant the agent high-privilege capabilities that would make such an attack impactful, and its behavior is limited to stylistic analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:29 AM
Security Audit — agent-trust-hub — naming-conventions