skills/base44/skills/base44-sandbox/Gen Agent Trust Hub

base44-sandbox

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes files and documentation from the remote sandbox and the vendor URL https://app.base44.com/api/sandbox/<APP_ID>/local-agent/readme.md. This ingestion creates a surface for indirect prompt injection where malicious content in the remote source could influence agent behavior. * Ingestion points: read_file, grep tools, and remote README URL. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified. * Capability inventory: run_command, write_file, and OAuth connector management. * Sanitization: No sanitization of external content is mentioned.
  • [COMMAND_EXECUTION]: The skill utilizes the run_command (or sandbox run) tool to execute shell commands within the remote cloud sandbox environment for tasks like building, linting, and verifying code.
  • [EXTERNAL_DOWNLOADS]: Fetches application-specific documentation and configuration files from the vendor's infrastructure at app.base44.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 09:48 AM
Security Audit — agent-trust-hub — base44-sandbox