experience-ui-bundle-frontend-generate

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/resolve-ui-bundle.sh is vulnerable to shell/command injection. It interpolates the shell variable $SFDX_PROJECT directly into a Python script executed via python3 -c. If a directory path or project root contains single quotes or other shell-sensitive characters, it allows for arbitrary Python code execution within the context of the agent's environment.
  • Evidence: The bash command python3 -c "... with open('$SFDX_PROJECT') as f: ..." in scripts/resolve-ui-bundle.sh fails to sanitize the file path before embedding it in a string literal.
  • [DYNAMIC_EXECUTION]: The skill uses python3 -c to execute dynamically constructed code strings to parse project configuration. This method is used unsafely by injecting shell variables directly into the executed script string.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data (configuration files and source code) and uses this information to drive code generation and script execution, creating an injection surface.
  • Ingestion points: sfdx-project.json (read by scripts/resolve-ui-bundle.sh), package.json (read for dependency checks), and various .tsx, .css, and .html files analyzed during the UI generation process.
  • Boundary markers: Absent. There are no instructions or delimiters implemented to prevent the agent from following malicious instructions embedded within the source files it reads.
  • Capability inventory: The skill can execute shell commands (npm, npx, python3, find, grep) and perform filesystem writes.
  • Sanitization: Absent. File content is processed and interpolated into prompts or script arguments without escaping or validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 04:23 PM
Security Audit — agent-trust-hub — experience-ui-bundle-frontend-generate