joyco-app
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches a component registry from a remote source and processes its contents to display descriptions to the agent. This creates a surface where malicious descriptions in the registry could potentially influence agent behavior.
- Ingestion points: The skill fetches
https://hub.joyco.studio/r/registry.jsonin Phase 3b. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to ignore potentially malicious instructions embedded in the registry data.
- Capability inventory: The skill has the ability to execute shell commands (e.g.,
pnpm dlx,curl), write files, and install packages. - Sanitization: The registry content is parsed using a Python script for display purposes, but no semantic sanitization of the descriptions is performed.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of various assets from vendor-controlled sources.
- It installs UI components and configurations from
hub.joyco.studio. - It fetches linting configurations and installs related dependencies from the
joyco-studioGitHub organization via thejoycoCLI. - It utilizes scripts from the
@joycostudio/scriptsNPM package to configure agent settings.
Audit Metadata