stack-evaluation

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing official CLI tools and MCP servers from trusted sources including Google (Firebase), Vercel, Supabase, and Amazon (AWS) using standard package managers (npm, brew, uvx). Examples: npm install -g firebase-tools, brew install supabase/tap/supabase, uvx mcp-server-aws.
  • [COMMAND_EXECUTION]: The skill provides instructions to use various cloud CLIs (aws, gcloud, firebase, supabase, vercel, dotnet) to query pricing, project status, and resource usage. These commands are integral to the skill's purpose of infrastructure evaluation.
  • [DATA_EXFILTRATION]: Network operations via curl target official, well-known cloud provider endpoints (e.g., cloudbilling.googleapis.com, api.supabase.com, api.vercel.com, pricing.us-east-1.amazonaws.com) to retrieve pricing data or project-specific metrics.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) as it ingests untrusted data (user-proposed architecture components in custom-explorer/SKILL.md) and possesses significant tool capabilities (shell access to cloud CLIs). No specific boundary markers or sanitization logic are defined in the instructions to mitigate potentially malicious instructions embedded in the architecture briefs.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 07:44 AM
Security Audit — agent-trust-hub — stack-evaluation