frontend-delivery

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to use the shell MCP server, enabling the execution of shell commands via mcp__shell__run_short_command and mcp__shell__start_command as defined in agents/openai.yaml.
  • [EXTERNAL_DOWNLOADS]: The skill has the capability to fetch content from external URLs using mcp__docs_web__fetch_url and clone remote Git repositories using mcp__git__clone_git_repository.
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection where data from external sources could influence agent behavior.
  • Ingestion points: Untrusted external data enters the context via mcp__docs_web__search_web and mcp__docs_web__fetch_url tools.
  • Boundary markers: The instructions in SKILL.md and the prompt templates do not include delimiters or instructions to ignore embedded commands within fetched content.
  • Capability inventory: The skill possesses extensive tools, including shell execution (mcp__shell__run_short_command), file modification (mcp__workspace__write_file), and remote repository interaction (mcp__git__push_git_branch).
  • Sanitization: The skill lacks logic to sanitize, escape, or validate data retrieved from external URLs before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 07:53 PM
Security Audit — agent-trust-hub — frontend-delivery