app-builder

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requests and utilizes the Bash tool to execute initialization and installation commands for various frameworks such as Next.js, Nuxt, and FastAPI. Evidence is present across multiple project templates.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes natural language user requests that directly influence task planning and the execution of shell commands without sufficient sanitization. Ingestion points: Natural language user requests in SKILL.md. Boundary markers: Absent; user input is not delimited from the agent's internal instructions. Capability inventory: High-privilege tools including Bash, Write, Edit, and Agent coordination. Sanitization: Absent; no validation or filtering is applied to user-provided project requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — app-builder