use-artifacts
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script to scaffold artifact directories and files under the user's home directory at ~/.agents/artifacts/.
- [PROMPT_INJECTION]: The workflow involves ingesting data from external web research to generate artifact content, creating a surface for indirect prompt injection. Ingestion points include web research results; the skill implements basic HTML escaping for titles as a boundary marker; capabilities include file-system writes and local script execution; sanitization includes title escaping and directory slugifying.
Audit Metadata