build-daily-inspiration-sites
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Node.js script located at
scripts/validate_capture.mjsto perform manifest validation. While the script is local to the skill, it operates on user-controlled inputs. - [COMMAND_EXECUTION]: The
validate_capture.mjsscript is vulnerable to path traversal. It usespath.resolve()on file paths defined in themanifest.jsonfile without restricting them to the target article directory. This allows a malicious manifest to force the script to check for the existence and size of arbitrary files on the local system (e.g.,/etc/passwdor~/.ssh/id_rsa). - [PROMPT_INJECTION]: The skill implements an orchestration pattern that creates five new Codex tasks using templates in
references/thread-brief-contract.md. These templates ingest untrusted data frommanifest.jsonandcontent.md, creating an indirect prompt injection surface. - Ingestion points: Data is read from
manifest.json(titles, paths) andcontent.md(detailed prompts) inSKILL.md(Step 1 and Step 3). - Boundary markers: The skill uses structured blocks (Identity, Evidence, Required task prompt) and instructions to replace all source content, which provides some mitigation against accidental obedience.
- Capability inventory: The generated tasks have access to the
@Sitesplugin for file writing and hosting, as well as the Codex in-app browser. - Sanitization: There is no evidence of string sanitization or filtering of the external content before it is interpolated into the sub-task briefs.
- [PROMPT_INJECTION]: Instructions in
SKILL.mddirect the agent to include absolute file paths in Markdown image syntax:![...] (<ABSOLUTE_FULL_PAGE_IMAGE_PATH>). If these paths are manipulated via the path traversal vulnerability, the sub-task environment might attempt to render sensitive local files, leading to data exposure within the agent's context.
Audit Metadata