app-builder

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill operates by analyzing arbitrary natural language requests from users to orchestrate application development, which constitutes an indirect prompt injection surface.
  • Ingestion points: User-provided project requirements and feature requests entering the agent context (as described in SKILL.md and project-detection.md).
  • Boundary markers: Absent; the instructions do not define delimiters or specific warnings to ignore embedded instructions within user-provided descriptions.
  • Capability inventory: The skill utilizes powerful tools including Bash, Write, Edit, and Agent to implement requested projects (listed in SKILL.md).
  • Sanitization: There is no documented logic for sanitizing or validating user input before it influences task planning or command execution.
  • [COMMAND_EXECUTION]: The skill's project templates frequently instruct the agent to execute shell commands for environment setup, dependency installation, and project execution (e.g., npm install, npx prisma init, pip install, uvicorn). These actions are core to the skill's stated purpose of application building.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — app-builder