scaffold-cli
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands to initialize the project environment, including
git init,pnpm install, andpnpm dlx ultracite. These are standard operations for a scaffolding tool. - [EXTERNAL_DOWNLOADS]: The skill downloads the
ultracitetoolchain initializer and project dependencies from the npm registry, which is a well-known and expected service for this task. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied project metadata (such as name, description, and repository URL) to populate template files. The provided templates include security helpers (e.g.,
containedPath,assertSafeId) specifically designed to prevent injection and path traversal vulnerabilities in the resulting CLI application. - [DATA_EXPOSURE]: The generated
.gitignoretemplate correctly includes sensitive files like.envand.env.localto prevent accidental credential leakage in the scaffolded projects.
Audit Metadata