scaffold-exercises
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
mkdir -pfor directory creation,git commitandgit mvfor repository management, andpnpm ai-hero-cli internal lintto validate the created structure (SKILL.md). - [PROMPT_INJECTION]: The skill processes user-provided 'plans' to determine directory names and file content without explicit sanitization or boundary markers, creating a surface for indirect prompt injection (SKILL.md). * Ingestion points: The user-supplied 'plan' extracted in the workflow. * Boundary markers: Absent for the plan input. * Capability inventory: Shell command execution via
mkdir,git, andpnpm(SKILL.md). * Sanitization: No validation is mentioned for directory names or readme content derived from the plan.
Audit Metadata