hostinger-headless

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads a bootstrap script (bootstrap.mjs) from the official Hostinger GitHub repository to manage the initial setup and authentication.\n- [REMOTE_CODE_EXECUTION]: It executes the downloaded bootstrap script using Node.js and installs the Hostinger MCP server tools via npx. These are vendor-provided resources used for the skill's primary functionality.\n- [COMMAND_EXECUTION]: Shell commands such as node, curl, and npx are utilized to verify the environment, perform health checks on deployed sites, and run automation scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data and fetches content from Hostinger's public storefront and WordPress APIs.\n
  • Ingestion points: User prompts, .hostinger/site.json, Storefront API, and WordPress REST API.\n
  • Boundary markers: Not explicitly defined for external API content.\n
  • Capability inventory: Shell command execution, site provisioning tools, and project file updates.\n
  • Sanitization: Data is processed as structured project configuration or rendered as content within the generated site.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:54 PM
Security Audit — agent-trust-hub — hostinger-headless