web-artifacts-builder
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of shell scripts to automate the development workflow.
scripts/init-artifact.shexecutespnpm create vite,pnpm install, andtarto set up the project environment.scripts/bundle-artifact.shusesparcelandhtml-inlineto build and consolidate assets into a single file.- [EXTERNAL_DOWNLOADS]: The initialization and bundling scripts download numerous packages from the NPM registry.
- Fetches well-known frontend libraries including Vite, Tailwind CSS, Radix UI primitives, and various shadcn/ui dependencies.
- Reference patterns in
references/artifact-patterns.mdinclude links to well-known services such asunpkg.comandcdn.tailwindcss.comfor library loading. - [DYNAMIC_EXECUTION]: The
scripts/init-artifact.shfile usesnode -eto programmatically update JSON configuration files. - Specifically, it executes inline JavaScript to modify
tsconfig.jsonandtsconfig.app.jsonto add path aliases (@/*). - [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for handling user-controlled data that could serve as injection surfaces if not properly sanitized by the implementer.
references/artifact-patterns.mdincludes examples for handling form data (FormData), URL hash state (window.location.hash), and Local Storage persistence.- Ingestion points: User input via forms and URL fragments.
- Boundary markers: None present in the template code.
- Capability inventory: Scripts perform file writes and network installs via
pnpm. - Sanitization: The provided patterns do not include explicit sanitization or validation logic for the ingested data.
Audit Metadata