experience-ui-bundle-frontend-generate
Warn
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/resolve-ui-bundle.shis vulnerable to shell/command injection. It interpolates the shell variable$SFDX_PROJECTdirectly into a Python script executed viapython3 -c. If a directory path or project root contains single quotes or other shell-sensitive characters, it allows for arbitrary Python code execution within the context of the agent's environment. - Evidence: The bash command
python3 -c "... with open('$SFDX_PROJECT') as f: ..."inscripts/resolve-ui-bundle.shfails to sanitize the file path before embedding it in a string literal. - [DYNAMIC_EXECUTION]: The skill uses
python3 -cto execute dynamically constructed code strings to parse project configuration. This method is used unsafely by injecting shell variables directly into the executed script string. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data (configuration files and source code) and uses this information to drive code generation and script execution, creating an injection surface.
- Ingestion points:
sfdx-project.json(read byscripts/resolve-ui-bundle.sh),package.json(read for dependency checks), and various.tsx,.css, and.htmlfiles analyzed during the UI generation process. - Boundary markers: Absent. There are no instructions or delimiters implemented to prevent the agent from following malicious instructions embedded within the source files it reads.
- Capability inventory: The skill can execute shell commands (
npm,npx,python3,find,grep) and perform filesystem writes. - Sanitization: Absent. File content is processed and interpolated into prompts or script arguments without escaping or validation.
Audit Metadata