web-artifacts-builder

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell scripts to automate the development workflow.
  • scripts/init-artifact.sh executes pnpm create vite, pnpm install, and tar to set up the project environment.
  • scripts/bundle-artifact.sh uses parcel and html-inline to build and consolidate assets into a single file.
  • [EXTERNAL_DOWNLOADS]: The initialization and bundling scripts download numerous packages from the NPM registry.
  • Fetches well-known frontend libraries including Vite, Tailwind CSS, Radix UI primitives, and various shadcn/ui dependencies.
  • Reference patterns in references/artifact-patterns.md include links to well-known services such as unpkg.com and cdn.tailwindcss.com for library loading.
  • [DYNAMIC_EXECUTION]: The scripts/init-artifact.sh file uses node -e to programmatically update JSON configuration files.
  • Specifically, it executes inline JavaScript to modify tsconfig.json and tsconfig.app.json to add path aliases (@/*).
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for handling user-controlled data that could serve as injection surfaces if not properly sanitized by the implementer.
  • references/artifact-patterns.md includes examples for handling form data (FormData), URL hash state (window.location.hash), and Local Storage persistence.
  • Ingestion points: User input via forms and URL fragments.
  • Boundary markers: None present in the template code.
  • Capability inventory: Scripts perform file writes and network installs via pnpm.
  • Sanitization: The provided patterns do not include explicit sanitization or validation logic for the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — web-artifacts-builder