grow-website
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing missing sub-skills via the command
npx skills add wondelai/skills/<slug> --global. These resources are scoped to a third-party namespace. - [COMMAND_EXECUTION]: The agent is instructed to provide shell commands to the user to extend the agent's capabilities when a specific framework's skill is not present in the current environment.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from local project files to resume sessions and provide contextual recommendations.
- Ingestion points: Project artifacts located in the
docs/folder, includingGROW-WEBSITE-PLAN.md,WEBSITE.md,METRICS.md,EXPERIMENTS.md,POSITIONING.md,MARKETING.md, andOFFER.md(SKILL.md). - Boundary markers: Absent; the skill is designed to read and incorporate existing file content directly into its operational context.
- Capability inventory: The skill possesses the ability to write/append to local markdown files and generate shell commands for sub-skill installation.
- Sanitization: Absent; the agent relies on the content of these files to determine the project's status and next steps without explicit validation of the data's integrity.
- [METADATA_POISONING]: The skill's internal metadata identifies 'wondelai' as the author, which differs from the system-provided author context ('emmraan').
Audit Metadata