Trust Assessment
frontend-design received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 2 findings: 0 critical, 0 high, 2 medium, and 0 low severity. Key findings include Unpinned CDN dependency for Tailwind CSS, Unpinned CDN dependency for Lucide icons.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 11, 2026 (commit 0676c56a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Unpinned CDN dependency for Tailwind CSS The skill suggests using a CDN link for Tailwind CSS that fetches the 'latest' version. Relying on unpinned 'latest' versions from a CDN can introduce supply chain risks, as a malicious update to the library or a compromise of the CDN could lead to the injection of harmful code into generated outputs if the agent uses this link. Pin the version of the CDN-hosted library to a specific, known-good version (e.g., `https://cdn.tailwindcss.com/3.4.3`) to ensure deterministic and secure dependency resolution. | Static | SKILL.md:99 | |
| MEDIUM | Unpinned CDN dependency for Lucide icons The skill suggests using a CDN link for Lucide icons that fetches the 'latest' version. Relying on unpinned 'latest' versions from a CDN can introduce supply chain risks, as a malicious update to the library or a compromise of the CDN could lead to the injection of harmful code into generated outputs if the agent uses this link. Pin the version of the CDN-hosted library to a specific, known-good version (e.g., `https://unpkg.com/lucide@0.303.0/dist/umd/lucide.min.js`) to ensure deterministic and secure dependency resolution. | Static | SKILL.md:109 |
Scan History
Embed Code
[](https://skillshield.io/report/e6edfbf3d62c7e9f)
Powered by SkillShield