artifacts-builder
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
init-artifact.shandbundle-artifact.sh) that perform significant environment modifications, including installing thepnpmpackage manager globally, initializing Vite projects, and executing build tools like Parcel. - [EXTERNAL_DOWNLOADS]: The initialization and bundling processes download and install a large number of dependencies from the NPM registry, including React, Vite, Tailwind CSS, and various UI component libraries.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a scaffolding tool where an agent or user provides the implementation logic. This creates an ingestion surface where untrusted code could be introduced into the build pipeline, though this is inherent to the tool's purpose as a development utility.
Audit Metadata