web-artifacts-builder

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The script scripts/init-artifact.sh includes a routine to install the pnpm package manager globally using npm install -g pnpm if it is not already present. This behavior modifies the global system environment and requires elevated permissions.
  • [DYNAMIC_EXECUTION]: The skill's scripts programmatically generate and modify project configuration and source files during the initialization and build processes.
  • Evidence: In scripts/init-artifact.sh, the skill uses cat to create postcss.config.js, tailwind.config.js, src/index.css, and components.json from heredoc templates.
  • Evidence: In scripts/init-artifact.sh, node -e is used to programmatically parse, modify, and rewrite tsconfig.json and tsconfig.app.json to inject path aliases.
  • Evidence: In scripts/bundle-artifact.sh, the skill creates a .parcelrc configuration file at runtime before initiating the build process.
  • [COMMAND_EXECUTION]: The skill relies on complex shell scripts to orchestrate the development environment, involving multiple subprocess calls.
  • Evidence: scripts/init-artifact.sh executes pnpm create, pnpm install, sed for template cleaning, and tar to extract a pre-packaged component library (shadcn-components.tar.gz).
  • Evidence: scripts/bundle-artifact.sh executes parcel build and html-inline to process and bundle the application into a single file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — web-artifacts-builder