daisyui
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the 'daisyui' package from the official npm registry. This is a standard dependency for the stated purpose and originates from a well-known, authoritative source.\n- [COMMAND_EXECUTION]: The skill includes shell commands like
grep,cat, andtestto inspect project files (such aspackage.jsonandcomponents.json) for configuration signals. These are standard, read-only diagnostic operations used for environment detection.\n- [PROMPT_INJECTION]: The skill instructions involve the agent reading output from shell commands that process project files, which constitutes a surface for indirect prompt injection. This is standard and expected behavior for repository-based development skills.\n - Ingestion points: Output from
grep,cat, andnpm lsas described inSKILL.md.\n - Boundary markers: None present.\n
- Capability inventory: Shell command execution and package management (npm).\n
- Sanitization: None present.
Audit Metadata