higgsfield-websites
Build Full-Stack Websites with Higgsfield
Building a production website requires design, infrastructure, security, and deployment decisions. This skill guides Claude or Codex through a structured Higgsfield CLI workflow.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "higgsfield-websites" from https://skillstore.io/skills/higgsfield-ai-higgsfield-websites.md and its manifest at https://skillstore.io/api/skills/higgsfield-ai-higgsfield-websites/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "higgsfield-websites". Create a portfolio for an architectural photographer with project galleries and contact details.
Expected outcome:
A responsive portfolio with original visual assets, project routes, accessible navigation, metadata, and a release-ready deployment summary.
Using "higgsfield-websites". Build an authenticated app that generates short product videos and tracks previous jobs.
Expected outcome:
A Quanta-based app with Higgsfield sign-in, generation controls, credit display, job polling, history, result previews, and failure states.
Using "higgsfield-websites". Add object storage and secure file uploads to my existing website.
Expected outcome:
An updated storage manifest, validated upload flow, authorization checks, size limits, safe object keys, and verification results.
Security Audit
CriticalMost detections are false positives caused by Markdown examples and defensive security guidance. The skill still executes an unverified remote installer, imports unpinned third-party components, and defaults to public deployment. It also attempts to override other skills and obscures deployment operations from users.
Confirmed security concerns (4)
Capability review items (9)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (50)
๐ Filesystem access (9)
โ๏ธ External commands (50)
๐ Env variables (13)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/higgsfield-ai-higgsfield-websites?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/higgsfield-ai-higgsfield-websites?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/higgsfield-ai-higgsfield-websites/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/higgsfield-ai-higgsfield-websites.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
higgsfield-ai. (2026). higgsfield-websites security audit report (audit version 3) [Author version 0.12.0]. Skillstore. https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3BibTeX citation
@techreport{higgsfield-ai-higgsfield-ai-higgsfield-websites-2026,
author = {higgsfield-ai},
title = {higgsfield-websites security audit report (audit version 3)},
institution = {Skillstore},
year = {2026},
number = {3},
url = {https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3},
note = {Author version 0.12.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "higgsfield-websites security audit report (audit version 3)"
version: "0.12.0"
type: report
authors:
- name: "higgsfield-ai"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3"
identifiers:
- type: other
value: "skillstore:higgsfield-ai-higgsfield-websites:audit:3"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Launch a Marketing Website
Create a branded landing site with generated assets, responsive pages, metadata, and Cloudflare deployment.
Build a Higgsfield Generation App
Create an authenticated Quanta interface for media generation, job tracking, credits, history, and result delivery.
Maintain a Deployed Product
Update routes, components, storage, integrations, or copy while preserving required checks and publication metadata.
Try These Prompts
Build a standalone website for [business]. Use [brand details], create essential pages, and request approval before public deployment.
Create a Higgsfield app for [workflow]. Include authentication, generation controls, result history, loading states, errors, and a Quanta interface.
Edit my existing [website or app]. Change [features], preserve current behavior, run required checks, and explain deployment impact before publishing.
Build [product] with D1, R2, and [integration]. Define threats, validate authorization, test failure states, and confirm every external release.
Best Practices
- Confirm product type, branding, integrations, and public-release intent before creating or deploying.
- Keep secrets in platform bindings and review every third-party dependency or generated component.
- Run type checks, quality gates, authorization reviews, and accessibility checks before release.
Avoid
- Do not pipe remote installers into a shell or use unpinned component registries.
- Do not deploy a live public site when the user requested only a local build or edit.
- Do not expose secrets, bypass server-side authorization, or send raw files through JSON.
Frequently Asked Questions
What is the difference between a website and an app?
Which tools are required?
Can I preview before deployment?
Can a standalone website use generated visual assets?
How does the skill handle security?
What is the difference between deploy and publish?
Developer Details
Author
higgsfield-aiLicense
MIT
Author version
v0.12.0
Skillstore revision
r2
Ref
c43861a65bb95efcae259cd161c9d6f4dc7eec6f
Maintenance freshness
7/25/2026
Usage
2 downloads ยท 0 views
File structure
๐ references/
๐ app-cover.md
๐ app-flow.md
๐ app-layouts.md
๐ app-quickstart.md
๐ asset-system.md
๐ auth.md
๐ containers.md
๐ design-recipe.md
๐ fnf-react.md
๐ fnf-sdk.md
๐ image-to-code.md
๐ quanta-design.md
๐ reference-boards.md
๐ review-rubric.md
๐ runtime-and-infra.md
๐ security.md
๐ seo.md
๐ website-flow.md
๐ wow-catalog.md
๐ wow-maker.md
๐ SKILL.md