brainstorming

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages a local Node.js server via shell scripts (scripts/start-server.sh and scripts/stop-server.sh). This server is used to host a visual companion UI in the user's browser.
  • [DYNAMIC_EXECUTION]: The visual companion dynamically renders HTML fragments generated by the agent during the brainstorming process. The server monitors a project-specific directory for new HTML files to serve.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection through the ingestion of external data.
  • Ingestion points: The skill reads existing project files, documentation, recent commits, and user interaction events captured by the browser companion (state_dir/events).
  • Boundary markers: The SKILL.md file includes a <HARD-GATE> requiring explicit user approval before the agent proceeds to implementation actions.
  • Capability inventory: The skill can spawn background processes (Node.js server), read and write files within a session-specific directory, and execute shell commands to launch the user's browser.
  • Sanitization: The server script utilizes isRegularFileInsideContentDir with fs.realpathSync to protect against directory traversal attacks and implements a random session token (32 bytes) to authenticate connections to the local server.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — brainstorming