lavish
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the lavish-axi package from the official npm registry using npx -y.
- [REMOTE_CODE_EXECUTION]: Executes the lavish-axi CLI tool from the npm registry and instructs the agent to fetch and follow instructions from the CLI output rather than the local SKILL.md file.
- [COMMAND_EXECUTION]: Runs shell commands using npx to access subcommands for design, playbook, and artifact generation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context and user arguments to generate HTML, creating a vulnerability surface for injected instructions.
- Ingestion points: $ARGUMENTS and conversation history (SKILL.md).
- Boundary markers: None; the instructions do not provide delimiters or warnings to ignore instructions embedded within the data.
- Capability inventory: Shell command execution via npx (SKILL.md).
- Sanitization: No validation or sanitization is performed on user-provided data before it is passed to the visualization tool.
Audit Metadata