webflow-code-component:pre-deploy-check

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill verifies the installation of vendor-specific Node.js packages like @webflow/webflow-cli, @webflow/react, and @webflow/data-types, as well as industry-standard tools such as tailwindcss, sass, and less. These are well-known or vendor-owned resources used for development tasks.\n- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it instructs the agent to ingest and analyze untrusted data from user-controlled files like webflow.json and React component source files.\n
  • Ingestion points: Analyzes project configuration files and component source code within the user's workspace.\n
  • Boundary markers: Absent. There are no specific instructions or delimiters provided to the agent to distinguish between file data and potential instructions embedded in the code or comments.\n
  • Capability inventory: The agent performs file system reading, pattern matching, and configuration analysis based on the ingested content.\n
  • Sanitization: Absent. The skill does not define methods for sanitizing or escaping the content of the analyzed files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 06:34 PM
Security Audit — agent-trust-hub — webflow-code-component:pre-deploy-check