app-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided natural language to create architectural plans and generate code, which is then used in file-writing and command-execution tasks. Ingestion points: User requests processed by the orchestrator (SKILL.md) and project-detection.md. Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious instructions embedded in the user request. Capability inventory: The orchestrator has access to high-privilege tools including Bash, Write, Edit, and Agent (for multi-agent coordination). Sanitization: The skill lacks specific mechanisms for sanitizing or validating user input before it influences system-level actions or subsequent agent tasks.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run project initialization and dependency management commands (e.g., npm, npx, pip, flutter). These operations are part of the functional scaffolding process described in the template files.
  • [EXTERNAL_DOWNLOADS]: The skill triggers installations of various well-known third-party packages and frameworks from official registries (e.g., Next.js, Prisma, Tailwind) using tools like npm and npx during the project setup phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — app-builder