preview-screens

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Shell Command Execution with Variable Paths: The skill uses shell commands like open, xdg-open, and powershell.exe to display generated files (Step 7). It instructs the agent to use a working directory path derived from $ARGUMENTS. If this path input is not properly validated, it could potentially allow for command injection through crafted directory names.
  • Indirect Prompt Injection Surface: The skill ingests and processes various project files, including TSX source code and configuration files (Steps 1, 2, and 4). As these files represent untrusted data, they provide a surface for indirect prompt injection. Maliciously crafted comments or metadata in these files could attempt to influence agent behavior, although the skill's focus on static UI conversion and the absence of complex state handling mitigate this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 02:47 PM
Security Audit — agent-trust-hub — preview-screens