datahub-mfe-configure-app

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local scripts provided within the project repository to apply configuration changes.
  • Evidence: Executes scripts/dev/datahub-dev.sh rebuild --wait to rebuild Docker containers in the standard development workflow.
  • Evidence: Executes cd datahub-frontend/run && ./run-local-frontend to restart the application server during direct local development.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for input interpolation by gathering values from the user and inserting them into configuration files and shell command execution paths.
  • Ingestion points: User-provided values for MFE name, path, and remote entry URL are collected via the AskQuestion tool in SKILL.md.
  • Capability inventory: The skill performs file write operations to datahub-frontend/conf/mfe.config.dev.yaml and datahub-frontend/conf/mfe.config.local.yaml, and triggers subsequent shell script executions.
  • Boundary markers: The values are delimited within a generated YAML configuration block, providing structural boundaries.
  • Sanitization: The skill relies on the user to provide valid configuration strings and does not perform explicit escaping or validation within the instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:43 AM
Security Audit — agent-trust-hub — datahub-mfe-configure-app