Back to skill

Security audit

Bestax: Theming

Security checks for vulnerabilities and agentic risk

Overview

This skill is a theming reference for a UI library and does not show hidden, privileged, destructive, or deceptive behavior.

Review the theming guidance like any frontend documentation: it can change app-wide visual behavior when used at the root, especially dark mode and class prefix settings, but the artifact does not ask for sensitive access or unsafe execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (55)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/css-variables.md (reported line 84)May include surrounding context.

md
## Scheme, text, background, border (light/dark surfaces)

| Variable                                                                          | Role                                                                                                                                                       |
| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--bulma-scheme-h`, `--bulma-scheme-s`                                            | scheme hue/saturation (`Theme`: `schemeH`, `schemeS`)                                                                                                      |
| `--bulma-scheme-main`, `--bulma-scheme-main-bis`, `--bulma-scheme-main-ter`       | page/surface backgrounds (main + subtle steps); `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline                          |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/css-variables.md (reported line 86)May include surrounding context.

md
| Variable                                                                          | Role                                                                                                                                                       |
| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--bulma-scheme-h`, `--bulma-scheme-s`                                            | scheme hue/saturation (`Theme`: `schemeH`, `schemeS`)                                                                                                      |
| `--bulma-scheme-main`, `--bulma-scheme-main-bis`, `--bulma-scheme-main-ter`       | page/surface backgrounds (main + subtle steps); `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline                          |
| `--bulma-scheme-invert`, `--bulma-scheme-invert-bis`, `--bulma-scheme-invert-ter` | inverted scheme surfaces; `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline (pair with a foreground — see the color guide) |
| `--bulma-background`                                                              | secondary background                                                                                                                                       |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/css-variables.md (reported line 89)May include surrounding context.

md
| `--bulma-scheme-h`, `--bulma-scheme-s`                                            | scheme hue/saturation (`Theme`: `schemeH`, `schemeS`)                                                                                                      |
| `--bulma-scheme-main`, `--bulma-scheme-main-bis`, `--bulma-scheme-main-ter`       | page/surface backgrounds (main + subtle steps); `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline                          |
| `--bulma-scheme-invert`, `--bulma-scheme-invert-bis`, `--bulma-scheme-invert-ter` | inverted scheme surfaces; `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline (pair with a foreground — see the color guide) |
| `--bulma-background`                                                              | secondary background                                                                                                                                       |
| `--bulma-text`, `--bulma-text-strong`, `--bulma-text-weak`                        | body / emphasized / muted text                                                                                                                             |
| `--bulma-border`, `--bulma-border-weak`                                           | borders                                                                                                                                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/css-variables.md (reported line 90)May include surrounding context.

md
| `--bulma-scheme-main`, `--bulma-scheme-main-bis`, `--bulma-scheme-main-ter`       | page/surface backgrounds (main + subtle steps); `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline                          |
| `--bulma-scheme-invert`, `--bulma-scheme-invert-bis`, `--bulma-scheme-invert-ter` | inverted scheme surfaces; `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline (pair with a foreground — see the color guide) |
| `--bulma-background`                                                              | secondary background                                                                                                                                       |
| `--bulma-text`, `--bulma-text-strong`, `--bulma-text-weak`                        | body / emphasized / muted text                                                                                                                             |
| `--bulma-border`, `--bulma-border-weak`                                           | borders                                                                                                                                                    |

## Radius, typography

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/css-variables.md (reported line 91)May include surrounding context.

md
| `--bulma-scheme-invert`, `--bulma-scheme-invert-bis`, `--bulma-scheme-invert-ter` | inverted scheme surfaces; `Theme bulmaVars`-overridable, and the scheme `bgColor` values render them inline (pair with a foreground — see the color guide) |
| `--bulma-background`                                                              | secondary background                                                                                                                                       |
| `--bulma-text`, `--bulma-text-strong`, `--bulma-text-weak`                        | body / emphasized / muted text                                                                                                                             |
| `--bulma-border`, `--bulma-border-weak`                                           | borders                                                                                                                                                    |

## Radius, typography

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 49)May include surrounding context.

md
## Component `color` / `size` props (verbatim unions)

| Component          | `color` accepts                                                                                                                                                           | `size` accepts                                                            | Notes                                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 49)May include surrounding context.

md
## Component `color` / `size` props (verbatim unions)

| Component          | `color` accepts                                                                                                                                                           | `size` accepts                                                            | Notes                                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 52)May include surrounding context.

md
| Component          | `color` accepts                                                                                                                                                           | `size` accepts                                                            | Notes                                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isH
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 53)May include surrounding context.

md
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 82)May include surrounding context.

md
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 54)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 55)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 61)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 62)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 63)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 64)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 68)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 69)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 75)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 76)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 78)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 79)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 80)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 82)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/themeable-components.md (reported line 84)May include surrounding context.

md
| `Button`           | `primary \| link \| info \| success \| warning \| danger \| white \| light \| dark \| black \| text \| ghost`                                                             | `small \| normal \| medium \| large`                                      | adds `text`, `ghost`; also `isLight`, `isOutlined`, `isInverted`, `isRounded`                                                                       |
| `Notification`     | every `validColors` member (the `-bis`/`-ter` shades and the greys deprecated: no CSS, dev-warn, removed next major — see ⚠️)                                             | —                                                                         | also `isLight`                                                                                                                                      |
| `Tag`              | `primary \| link \| info \| success \| warning \| danger \| black \| dark \| light \| white`                                                                              | `normal \| medium \| large`                                               | also `isLight`, `isRounded`, `isDelete`, `isHoverable`                                                                                              |
| `Box`              | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | `color` renders `has-text-<color>`, same as `textColor` (which wins when both are set; no `.box.is-*` ships — tint via `bgColor`); also `hasShadow` |
| `Message`          | `primary \| link \| info \| success \| warning \| danger`                                                                                                                 | —                                                                         | the 6 only                                   
...[truncated 25 chars]

Static analysis

No suspicious patterns detected.