web-artifacts-builder

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (init-artifact.sh and bundle-artifact.sh) that perform complex filesystem operations and build steps using commands such as pnpm, sed, node, tar, and rm to manage the project lifecycle.\n- [EXTERNAL_DOWNLOADS]: The skill triggers the installation of many Node.js packages from the official NPM registry during project initialization and bundling. These include Vite, React, Tailwind CSS, and Radix UI components, which are well-known industry-standard libraries.\n- [PRIVILEGE_ESCALATION]: The init-artifact.sh script attempts to perform a global installation of the 'pnpm' package manager using npm install -g pnpm if it is not found on the system. Global installations modify system-wide directories and are a sensitive operation.\n- [INDIRECT_PROMPT_INJECTION]: The initialization script takes a user-provided project name through a command-line argument which is interpolated into shell commands.\n
  • Ingestion points: Command-line argument $1 (project name) in scripts/init-artifact.sh.\n
  • Boundary markers: None identified in the script logic to delimit the user input from the shell command context.\n
  • Capability inventory: Includes execution of shell commands (pnpm create, sed), directory creation, and file extraction.\n
  • Sanitization: The user input is used directly in shell interpolation without escaping or validation, posing a potential for command injection if malicious strings are provided.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — web-artifacts-builder