constructive-builder

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/check-scaffold.mjs script uses the Function constructor to evaluate data structures parsed from generated TypeScript files, which are derived from user-provided configuration.\n- [DYNAMIC_EXECUTION]: Browser-based QA logic in scripts/lib/live-qa/ utilizes eval and async Function wrappers to automate interactions and verify authentication states within the browser session.\n- [DYNAMIC_EXECUTION]: Multiple shell scripts (scripts/multi-turn-run.sh, scripts/verify-phase.sh) invoke node -e to perform dynamic JSON parsing and logic execution at runtime.\n- [COMMAND_EXECUTION]: The orchestration scripts perform various system-level operations by spawning child processes to run pnpm, psql, and process management commands like kill.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied YAML 'briefs' to generate and subsequently execute application code, creating an attack surface if the input data is maliciously crafted.\n- [EXTERNAL_DOWNLOADS]: The harness automatically downloads and integrates UI 'Blocks' via npx shadcn add from the author's verified GitHub Pages repository at https://constructive-io.github.io/dashboard/r/.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:07 PM
Security Audit — agent-trust-hub — constructive-builder