app-builder
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads dependencies and project boilerplates from official registries such as npm and PyPI. It relies on standard framework initializers like npx (for create-next-app and nuxi), expo-cli, and flutter-cli to bootstrap projects.
- [COMMAND_EXECUTION]: Shell commands are executed via Bash to manage project lifecycles, including installing packages, running database migrations, and configuring local development environments across multiple tech stack templates.
- [PROMPT_INJECTION]: The skill processes untrusted natural language requests to determine application scope and architecture, creating a potential surface for indirect prompt injection.
- Ingestion points: Natural language user requests define the project goals in
SKILL.md. - Boundary markers: The orchestration logic enforces a mandatory
PLAN.mdcreation and verification step inagent-coordination.mdto structure the agent's work before code generation. - Capability inventory: The skill possesses extensive capabilities including
Bashaccess, fileWrite/Editpermissions, and the ability to coordinate specialized sub-agents. - Sanitization: Security relies on the structured multi-agent workflow and verification checkpoints rather than explicit programmatic input sanitization.
Audit Metadata