frontpage-vote-dev
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches resources from the vendor's repository (DFectuoso/frontpage-sh-skills-dev) to set up the development environment.\n- [COMMAND_EXECUTION]: Executes curl, jq, and the mppx CLI for querying proposals and submitting votes to a development instance.\n- [PROMPT_INJECTION]: Identified an indirect prompt injection surface where untrusted data from an API ($FRONTPAGE_BASE_URL/api/proposals in SKILL.md) is ingested into the agent context. No boundary markers or sanitization are present, and the agent has access to capabilities like mppx and curl for subsequent actions. However, the risk is considered low due to the development-only nature of the tool.
Audit Metadata