building-web-artifacts
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies heavily on shell command execution for its core functionality. The
init-artifact.shandbundle-artifact.shscripts invokepnpm,npm,bash,tar,sed, andnodeto manage project directories, install dependencies, and process build files. - [INDIRECT_PROMPT_INJECTION]: The
init-artifact.shscript is vulnerable to argument and command injection because it accepts a user-provided project name and uses it directly in shell commands and text-processing operations without sanitization. - Ingestion points: Project name argument (
$1) inscripts/init-artifact.sh. - Boundary markers: None; input is used directly in string interpolation.
- Capability inventory: File system access, shell execution, and dependency installation via
pnpmandsed. - Sanitization: Absent; the input can break out of shell quoting or
seddelimiters to execute unintended logic. - [METADATA_POISONING]: The
LICENSE.txtfile contains a copyright notice attributed to "Anthropic, PBC", which is inconsistent with the skill's authorship and may mislead users regarding the origin and safety review status of the skill. - [PRIVILEGE_ESCALATION]: The
init-artifact.shscript attempts to perform a global installation of thepnpmpackage manager usingnpm install -g, which typically requires elevated system privileges. - [EXTERNAL_DOWNLOADS]: The skill downloads a wide range of frontend development dependencies from the official NPM registry during project initialization and bundling phases.
Audit Metadata