flask-app-builder

Fail

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Multiple files contain hardcoded sensitive credentials.
  • references/app-registry.md includes plaintext passwords for several live applications, such as 'liberty2026', 'sweetspot2026', and 'admin1234'.
  • references/app-registry.md contains an active 'Willie FloodClaim token' and a 'Cakely token' in plaintext.
  • references/app-registry.md references sensitive local file paths containing authentication tokens, such as /root/.secrets/github_token, /root/.secrets/gitlab_token, and /root/.secrets/ecdash_token.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for downloading scripts from a remote repository.
  • references/playwright-patterns.md provides curl commands to fetch Python scripts from the author's GitHub organization repository.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of scripts for application testing and security auditing.
  • SKILL.md and references/playwright-patterns.md describe executing local and remotely-sourced Python scripts using python3 to automate testing workflows.
  • [PROMPT_INJECTION]: The skill includes code patterns for an AI chat interface that processes untrusted user data.
  • references/feature-patterns.md defines an /api/chat endpoint that sends user-supplied messages directly to the OpenRouter API without demonstrated sanitization or boundary markers, creating a surface for indirect prompt injection.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 06:13 AM
Security Audit — agent-trust-hub — flask-app-builder