experience-lwc-security-validate

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate security auditing tool developed by a trusted vendor (forcedotcom). All capabilities, including local script execution (python3, jq) and file bundle reading, are directly tied to its purpose of LWS security validation. The scripts provided (check-lwc-import.sh and validate-sarif.sh) are well-structured utility tools used for import verification and output validation.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external Lightning Web Component code, which is an untrusted data source. This represents a potential attack surface for indirect prompt injection where malicious instructions could be embedded in code or comments. This risk is inherent to the skill's primary purpose (auditing code), and is addressed by specific instructions to detect obfuscation and bypass techniques.\n
  • Ingestion points: Target Lightning Web Component bundle files (.js, .ts, .html, .css, .js-meta.xml) read during the audit process.\n
  • Boundary markers: The agent is constrained by a specific rule catalog (lws-001 through lws-023b) and mandatory output templates (SARIF or markdown).\n
  • Capability inventory: Execution of local scripts using python3 and jq for specific validation tasks.\n
  • Sanitization: The skill outputs findings in structured formats following a strict schema and rule catalog, reducing the risk of injection into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:35 PM
Security Audit — agent-trust-hub — experience-lwc-security-validate