frontend
Warn
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions in LITE.md direct the agent to read .env files to identify API base URLs and client configuration. Accessing environment files exposes sensitive credentials and configuration secrets to the agent's context within the GROUND phase of the workflow.
- [PROMPT_INJECTION]: The skill ingests untrusted data from local project files (e.g., package.json, .env, source code) using shell commands (cat, ls, npm, npx). The lack of explicit boundary markers or sanitization instructions for this data creates a surface for indirect prompt injection from malicious project files.
- Ingestion points: Project files including package.json, .env, and directories src/ or frontend/ (specified in LITE.md).
- Boundary markers: Absent; there are no instructions to delimit or ignore embedded instructions in the processed files.
- Capability inventory: The skill utilizes shell commands (cat, ls) and package managers (npm, npx) to interact with the filesystem and execute project-defined scripts.
- Sanitization: Absent; no filtering or validation of the ingested file content is specified.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute project-defined scripts using npm run build and npx jest based on findings in the local environment. This grants the agent the ability to execute arbitrary commands defined in the project's configuration files as part of the EXECUTE and VERIFY steps.
Audit Metadata