scaffold-exercises

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like mkdir, git commit, and git mv to automate directory creation and version control.
  • [COMMAND_EXECUTION]: It executes a local project CLI via pnpm ai-hero-cli internal lint to ensure created structures meet project standards.
  • [PROMPT_INJECTION]: The skill processes user-defined exercise plans to determine folder names. This creates an indirect prompt injection surface where a malicious plan could attempt to include shell metacharacters in directory names, requiring the agent to perform careful parsing as instructed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 06:26 PM
Security Audit — agent-trust-hub — scaffold-exercises