brainstorming
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill manages a local Node.js server via shell scripts (
scripts/start-server.shandscripts/stop-server.sh). This server is used to host a visual companion UI in the user's browser. - [DYNAMIC_EXECUTION]: The visual companion dynamically renders HTML fragments generated by the agent during the brainstorming process. The server monitors a project-specific directory for new HTML files to serve.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection through the ingestion of external data.
- Ingestion points: The skill reads existing project files, documentation, recent commits, and user interaction events captured by the browser companion (
state_dir/events). - Boundary markers: The
SKILL.mdfile includes a<HARD-GATE>requiring explicit user approval before the agent proceeds to implementation actions. - Capability inventory: The skill can spawn background processes (Node.js server), read and write files within a session-specific directory, and execute shell commands to launch the user's browser.
- Sanitization: The server script utilizes
isRegularFileInsideContentDirwithfs.realpathSyncto protect against directory traversal attacks and implements a random session token (32 bytes) to authenticate connections to the local server.
Audit Metadata