grow-website

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing missing sub-skills via the command npx skills add wondelai/skills/<slug> --global. These resources are scoped to a third-party namespace.
  • [COMMAND_EXECUTION]: The agent is instructed to provide shell commands to the user to extend the agent's capabilities when a specific framework's skill is not present in the current environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from local project files to resume sessions and provide contextual recommendations.
  • Ingestion points: Project artifacts located in the docs/ folder, including GROW-WEBSITE-PLAN.md, WEBSITE.md, METRICS.md, EXPERIMENTS.md, POSITIONING.md, MARKETING.md, and OFFER.md (SKILL.md).
  • Boundary markers: Absent; the skill is designed to read and incorporate existing file content directly into its operational context.
  • Capability inventory: The skill possesses the ability to write/append to local markdown files and generate shell commands for sub-skill installation.
  • Sanitization: Absent; the agent relies on the content of these files to determine the project's status and next steps without explicit validation of the data's integrity.
  • [METADATA_POISONING]: The skill's internal metadata identifies 'wondelai' as the author, which differs from the system-provided author context ('emmraan').
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — grow-website