demo-builder
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill researches prospect companies and competitors using
WebSearchandWebFetch(Phase 2 and Phase 5). This external data is used to generate demo concepts and build prototypes. There are no explicit instructions to sanitize this content or ignore instructions embedded within the retrieved data, creating a surface for indirect prompt injection. - Ingestion points: Phase 2 (Research), Phase 5 (Competitor research).
- Boundary markers: Absent.
- Capability inventory:
Bash(can execute commands),Write(can write files). - Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to build and test prototypes (Step 8 and 9). This involves executing code generated by the agent based on documentation and user input. While this is the primary purpose of the skill, it represents a high-capability execution environment.
Audit Metadata