frontend-delivery
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is configured to use the
shellMCP server, enabling the execution of shell commands viamcp__shell__run_short_commandandmcp__shell__start_commandas defined inagents/openai.yaml. - [EXTERNAL_DOWNLOADS]: The skill has the capability to fetch content from external URLs using
mcp__docs_web__fetch_urland clone remote Git repositories usingmcp__git__clone_git_repository. - [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection where data from external sources could influence agent behavior.
- Ingestion points: Untrusted external data enters the context via
mcp__docs_web__search_webandmcp__docs_web__fetch_urltools. - Boundary markers: The instructions in
SKILL.mdand the prompt templates do not include delimiters or instructions to ignore embedded commands within fetched content. - Capability inventory: The skill possesses extensive tools, including shell execution (
mcp__shell__run_short_command), file modification (mcp__workspace__write_file), and remote repository interaction (mcp__git__push_git_branch). - Sanitization: The skill lacks logic to sanitize, escape, or validate data retrieved from external URLs before it is processed by the agent.
Audit Metadata