senior-fullstack
Warn
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local Python scripts (e.g.,
scripts/fullstack_scaffolder.py) to perform its core functions, which involves executing code on the local system. - [NO_CODE]: The executable logic for the referenced scripts and the content of the reference documentation are missing from the provided skill files, preventing a full security audit of the tool's actions.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its analysis of user-provided project files.
- Ingestion points: The
Code Quality AnalyzerandProject Scaffolderscripts ingest data from untrusted project paths. - Boundary markers: No explicit delimiters or instructions are present to prevent the agent from obeying commands embedded within the analyzed code.
- Capability inventory: The description indicates the skill can perform 'automated fixes' and 'scaffolding,' implying it has file system write permissions.
- Sanitization: No evidence of sanitization or validation of the ingested code or project files is provided.
Audit Metadata