brainstorming
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill launches a local Node.js server via
scripts/start-server.shandscripts/server.cjs. This server runs as a background process to support visual brainstorming mockups. - [DATA_EXPOSURE]: The local server serves files from the session's content directory over HTTP. While it restricts access to that specific directory, it creates a local listening service that exposes the content of files intended for the brainstorming session.
- [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read interaction data from the
$STATE_DIR/eventsfile, which is populated by browser events. This data is untrusted as it originates from the browser environment and is merged into the agent's context. • Ingestion points: User interaction logs are read from the session state directory. • Boundary markers: No delimiters or protective instructions are provided to the agent for handling this external data. • Capability inventory: The agent has the ability to write files and execute shell commands. • Sanitization: The skill does not implement validation or sanitization of the browser event data before ingestion.
Audit Metadata