app-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest natural language requests from users to generate application code and structures.
  • Ingestion points: User-provided project descriptions enter the context through the orchestrator (SKILL.md).
  • Boundary markers: The skill implements a structured multi-phase pipeline defined in agent-coordination.md, which includes a mandatory checkpoint requiring a PLAN.md file to be verified before any specialist agents (e.g., Backend, Frontend) are invoked.
  • Capability inventory: The orchestrator is granted Bash, Write, Edit, and Agent tools to facilitate project scaffolding and deployment tasks.
  • Sanitization: While no specific regex-based sanitization is mentioned, the skill logic relies on the verification checkpoints and a structured planning phase to manage user input safely.
  • [EXTERNAL_DOWNLOADS]: The skill includes various project templates that direct the agent to install dependencies from official registries like NPM and PyPI.
  • Evidence: Templates such as templates/nuxt-app/TEMPLATE.md, templates/express-api/TEMPLATE.md, and templates/python-fastapi/TEMPLATE.md instruct the installation of well-known libraries including prisma, zod, fastapi, stripe, and bcrypt.
  • Context: All referenced tools and packages are industry-standard resources used for their intended development purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — app-builder