software-frontend
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a vast array of official documentation and community-standard repositories for frontend development (e.g., nextjs.org, react.dev, svelte.dev, vuejs.org, and various GitHub repositories under vercel-labs and remix-run). These are recognized as safe and trusted sources within the development ecosystem.
- [COMMAND_EXECUTION]: The provided templates and workflow instructions utilize standard development CLI tools, including npm, npx, ng (Angular CLI), and nuxi (Nuxt CLI). It also references a local script 'agents-skills-feedback-loop/scripts/append_learning.py' for internal feedback, which is an expected operational pattern for this type of managed skill.
- [INDIRECT_PROMPT_INJECTION]: The skill operates as a code-generation and architectural guidance tool, which involves processing user-provided task descriptions. While this provides an attack surface for indirect injection, the skill mitigates this by instructing the agent to perform verification checks on all generated code, specifically looking for hook violations, semantic errors, and missing accessibility roles before final sign-off.
Audit Metadata