scaffold
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches a documentation specification file from the vendor's official GitHub repository (
raw.githubusercontent.com/horizon-foundry/foundry/main/reference/doc-set-spec.md) to define the structure of the scaffolded project.\n- [COMMAND_EXECUTION]: Executes a shell command to perform a daily version check. The command usescurlto query a vendor-specific API (foundry.thehorizonfoundry.com) and manages a rate-limit state file in the user's home directory (~/.claude/.foundry-version-checked).\n- [INDIRECT_PROMPT_INJECTION]: The skill seeds a 'resume rule' in the project's documentation (CLAUDE.md) that instructs the agent to read and follow instructions from a phase plan index inTODOS.mdduring future sessions. This creates a surface where external or malicious modifications to these project files could influence agent behavior.\n - Ingestion points: Reads project-specific plans and backlog from
TODOS.mdand associated plan files; fetches template specifications from a remote repository.\n - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between data and instructions within the phase plan files.\n
- Capability inventory: Shell execution (
curl,find,mkdir,touch) and broad file system write access for project creation.\n - Sanitization: The skill does not describe mechanisms for sanitizing user-provided inputs or validating the integrity of instructions retrieved from phase plan files.
Audit Metadata