senior-fullstack
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements two Python-based CLI tools,
project_scaffolder.pyandcode_quality_analyzer.py, to handle project creation and code auditing. These tools operate on the local filesystem based on user-provided paths. - [DYNAMIC_EXECUTION]: The
project_scaffolder.pyscript generates source code, configuration files, and directory structures for various fullstack architectures (Next.js, FastAPI, MERN, and Django). This code generation follows pre-defined internal templates and is consistent with the skill's primary purpose. - [INDIRECT_PROMPT_INJECTION]: The code quality analysis tool processes external source code from project directories. This represents an indirect prompt injection surface as malicious content in the analyzed files could potentially influence the agent's context during the reporting phase.
- Ingestion points:
scripts/code_quality_analyzer.pyreads all code and configuration files within the directory specified by the user. - Boundary markers: The tool does not use specific delimiters or protective instructions when reading and displaying file content in its reports.
- Capability inventory: The skill has the capability to read files (
code_quality_analyzer.py) and write files to the local disk (project_scaffolder.py). - Sanitization: No sanitization or escaping is performed on the content read from external files before it is processed for analysis metrics.
Audit Metadata