smoke-test
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and executes the
create-mastraproject initializer and associated dependencies such as@mastra/stagehandand@mastra/agent-browserfrom official package registries. - [COMMAND_EXECUTION]: Executes shell commands to scaffold projects using various package managers including
npm,yarn,pnpm, andbun, and manages the local development server vianpm run dev. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied parameters (directory, name, tag) which are interpolated into shell commands.
- Ingestion points: The
ARGUMENTSstring parsed during the initial validation step. - Boundary markers: Not explicitly present in the shell command templates, though the skill provides instructions for the agent to validate input.
- Capability inventory: Shell execution (
npx,npm run dev), file system writes, and browser automation via Chrome MCP tools. - Sanitization: The instructions direct the agent to validate that names contain no special characters and that parameters for package managers and LLM providers match a predefined whitelist.
- [DYNAMIC_EXECUTION]: Dynamically generates a TypeScript file (
browser-agent.ts) with configuration based on user-selected providers and executes this code through the development server environment.
Audit Metadata