ce-prototype
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Node.js script (
light-webserver.js) to manage a preview environment. It usesbashfor directory setup and server lifecycle management. These operations include defensive checks for symlinks and file ownership before execution. - [DATA_EXFILTRATION]: The prototype server binds to the loopback interface (
127.0.0.1) by default. API endpoints for the annotation loop are protected by a randomly generated session token to prevent unauthorized access from other local processes. - [INDIRECT_PROMPT_INJECTION]: The skill handles user-provided annotations (comments and CSS selectors) through a web interface. The documentation in
references/annotation-loop.mdexplicitly instructs the agent to treat these inputs as untrusted and to never execute them as commands, correctly identifying and mitigating this attack surface. - [DYNAMIC_EXECUTION]: The
light-webserver.jsscript useschild_processmethods (spawn,execFileSync) exclusively for process management (e.g., checking if a server PID is alive). The PIDs are validated as integers before use, preventing command injection.
Audit Metadata