building-web-artifacts

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies heavily on shell command execution for its core functionality. The init-artifact.sh and bundle-artifact.sh scripts invoke pnpm, npm, bash, tar, sed, and node to manage project directories, install dependencies, and process build files.
  • [INDIRECT_PROMPT_INJECTION]: The init-artifact.sh script is vulnerable to argument and command injection because it accepts a user-provided project name and uses it directly in shell commands and text-processing operations without sanitization.
  • Ingestion points: Project name argument ($1) in scripts/init-artifact.sh.
  • Boundary markers: None; input is used directly in string interpolation.
  • Capability inventory: File system access, shell execution, and dependency installation via pnpm and sed.
  • Sanitization: Absent; the input can break out of shell quoting or sed delimiters to execute unintended logic.
  • [METADATA_POISONING]: The LICENSE.txt file contains a copyright notice attributed to "Anthropic, PBC", which is inconsistent with the skill's authorship and may mislead users regarding the origin and safety review status of the skill.
  • [PRIVILEGE_ESCALATION]: The init-artifact.sh script attempts to perform a global installation of the pnpm package manager using npm install -g, which typically requires elevated system privileges.
  • [EXTERNAL_DOWNLOADS]: The skill downloads a wide range of frontend development dependencies from the official NPM registry during project initialization and bundling phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — building-web-artifacts