impeccable

Warn

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: MEDIUMPERSISTENCEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PERSISTENCE]: The pin command (scripts/pin.mjs) creates new skill definitions in agent-specific directories (e.g., .claude/skills, .cursor/skills). This allows the skill to install standalone shortcuts that persist across sessions and modify the agent's available toolset. Additionally, scripts/live-inject.mjs and scripts/hook-lib.mjs automatically add tool-specific files and configuration to .git/info/exclude and .gitignore to maintain a persistent but hidden state within the user's project.
  • [PRIVILEGE_ESCALATION]: The skill modifies the agent's own configuration environment by writing to harness directories outside of its own installation folder. This behavior is used to create command shortcuts but represents a pattern of acquiring more influence over the agent's behavior than a typical skill.
  • [INDIRECT_PROMPT_INJECTION]: The live-server.mjs script establishes a communication channel between the user's web browser and the AI agent. It accepts steer events containing natural language messages directly from the browser and passes them to the agent's poll loop (scripts/live-poll.mjs). This creates an attack surface where a malicious website or project being designed could inject instructions into the agent's context. 1. Ingestion points: scripts/live-server.mjs (via /events and /manual-edit-stash endpoints). 2. Boundary markers: Missing; the agent is instructed to follow the incoming messages as design direction. 3. Capability inventory: Subprocess execution (spawn, execFileSync), file system writes (fs.writeFileSync), and network operations (fetch). 4. Sanitization: Limited to basic JSON validation in scripts/live/event-validation.mjs.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands and other CLI agents. Specifically, scripts/live-copy-edit-agent.mjs invokes the codex CLI with the --dangerously-bypass-approvals-and-sandbox flag and the claude CLI with the --permission-mode bypassPermissions flag to perform automated edits. It also uses execFileSync to run Git commands for project state analysis in scripts/context-signals.mjs.
  • [EXTERNAL_DOWNLOADS]: The skill performs an automated update check by fetching version information from https://impeccable.style in scripts/context.mjs. Furthermore, the detector engine in scripts/detector/engines/browser/detect-url.mjs uses puppeteer to download and render arbitrary external URLs provided by the user or discovered in the project.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — impeccable