coming-soon
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill directs the agent to obtain authentication credentials from the local path
~/.build-host/credentials.json. - [DATA_EXFILTRATION]: The skill transmits generated site content and deployment requests to external build.host API endpoints.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the processing of untrusted user-provided project briefs.
- Ingestion points: The user-provided project brief used for content generation in the operating procedure.
- Boundary markers: No delimiters or safety instructions are defined to isolate the brief content from the agent's instructions.
- Capability inventory: The agent can write files to the project directory and perform network deployments via the build.host API.
- Sanitization: No specific sanitization or validation of the brief's content is performed before the site code is generated and shipped.
Audit Metadata