create-artifact

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill uses curl to POST the contents of local files (e.g., report.md, page.html) to an external API (api.folslate.com). This constitutes exfiltration of local data to a third-party domain that is not included in the trusted vendor list.
  • [COMMAND_EXECUTION]: The skill instructions provide shell commands (curl) for the agent to execute in order to perform the upload, which involves direct interaction with the underlying system shell.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process local files for external upload. This creates an attack surface where malicious content embedded in those files could attempt to influence the agent's behavior during the processing phase.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 04:54 PM
Security Audit — agent-trust-hub — create-artifact