generate-feature-package

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Node.js script via the Bash tool to perform file system operations. The command structure interpolates user-provided input directly into a shell string: node "<skill-dir>/scripts/scaffold-feature.mjs" <name>.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection where a malicious user could provide a feature name containing shell metacharacters to attempt command execution.
  • Ingestion points: The <name> argument in SKILL.md derived from user input.
  • Boundary markers: None explicitly defined for the argument interpolation in the bash command.
  • Capability inventory: Uses the Bash tool to execute shell commands and the underlying script performs file system modifications via mkdirSync and writeFileSync.
  • Sanitization: The agent is instructed to convert input to kebab-case before execution, and the script itself validates the name against a strict whitelist regex (/^[a-z][a-z0-9]*(-[a-z0-9]+)*$/) that blocks shell metacharacters and path traversal.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:27 AM
Security Audit — agent-trust-hub — generate-feature-package