web-artifacts-builder
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
init-artifact.shandbundle-artifact.sh) that perform complex filesystem operations and build steps using commands such aspnpm,sed,node,tar, andrmto manage the project lifecycle.\n- [EXTERNAL_DOWNLOADS]: The skill triggers the installation of many Node.js packages from the official NPM registry during project initialization and bundling. These include Vite, React, Tailwind CSS, and Radix UI components, which are well-known industry-standard libraries.\n- [PRIVILEGE_ESCALATION]: Theinit-artifact.shscript attempts to perform a global installation of the 'pnpm' package manager usingnpm install -g pnpmif it is not found on the system. Global installations modify system-wide directories and are a sensitive operation.\n- [INDIRECT_PROMPT_INJECTION]: The initialization script takes a user-provided project name through a command-line argument which is interpolated into shell commands.\n - Ingestion points: Command-line argument
$1(project name) inscripts/init-artifact.sh.\n - Boundary markers: None identified in the script logic to delimit the user input from the shell command context.\n
- Capability inventory: Includes execution of shell commands (
pnpm create,sed), directory creation, and file extraction.\n - Sanitization: The user input is used directly in shell interpolation without escaping or validation, posing a potential for command injection if malicious strings are provided.
Audit Metadata