scaffold-python-recipe
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [Input Validation and Path Traversal Protection]: The
scaffold.pyscript implements rigorous validation for user-provided inputs. It explicitly checks for path traversal segments (e.g.,..) and restricts output to an allow-list of directories. These controls ensure that the script only modifies intended locations within the workspace. - [Command Execution]: The skill's integration test template (
test_server_e2e.py) usessubprocess.Popento start a local development server for testing. This is a standard pattern for end-to-end tests and is implemented using a list of arguments, which is a recommended practice to prevent command injection. - [Indirect Prompt Injection Surface]: The skill processes external data (recipe name and output directory) to generate files. The ingestion points are located in
scripts/scaffold.py. The skill's capabilities include file-system write operations, but the risk is managed through validation logic that enforces naming conventions and prevents path traversal, ensuring that only expected operations are performed.
Audit Metadata