brainstorming

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill launches a local Node.js server via scripts/start-server.sh and scripts/server.cjs. This server runs as a background process to support visual brainstorming mockups.
  • [DATA_EXPOSURE]: The local server serves files from the session's content directory over HTTP. While it restricts access to that specific directory, it creates a local listening service that exposes the content of files intended for the brainstorming session.
  • [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read interaction data from the $STATE_DIR/events file, which is populated by browser events. This data is untrusted as it originates from the browser environment and is merged into the agent's context. • Ingestion points: User interaction logs are read from the session state directory. • Boundary markers: No delimiters or protective instructions are provided to the agent for handling this external data. • Capability inventory: The agent has the ability to write files and execute shell commands. • Sanitization: The skill does not implement validation or sanitization of the browser event data before ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — brainstorming