project-min-evaluation
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill triggers the execution of shell commands through local package managers (SKILL.md).
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes external data (project configuration files) to determine which commands to run, creating a surface for indirect injection.
- Ingestion points: The agent reads script definitions and the packageManager field from the repository's package.json (SKILL.md).
- Boundary markers: No instructions are provided to the agent to inspect or validate the safety of the scripts before running them.
- Capability inventory: The skill possesses the ability to execute arbitrary strings defined in the scripts section of the project manifest via the system shell.
- Sanitization: There is no evidence of sanitization or filtering of the script values retrieved from the project files.
Audit Metadata