artifacts-builder
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/init-artifact.shscript is vulnerable to command injection via the project name argument ($1). The script uses the$PROJECT_NAMEvariable inside asedcommand string with mixed quoting:$SED_INPLACE 's/<title>.*<\/title>/<title>'"$PROJECT_NAME"'<\/title>/' index.html. This construction allows an attacker to provide a project name that breaks out of thesedcommand context and executes arbitrary shell commands on the host system.\n- [EXTERNAL_DOWNLOADS]: The skill's scripts (scripts/init-artifact.shandscripts/bundle-artifact.sh) perform multiple automated installations of Node.js packages usingpnpm. These include core development tools like Vite and Parcel, along with numerous frontend libraries such as Tailwind CSS and Radix UI components. While these are standard tools, they represent an external dependency surface that is automatically downloaded and installed during the skill's operation.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the generation of elaborate multi-component HTML artifacts based on user requests. This process involves the agent taking high-level instructions to produce HTML, CSS, and JavaScript, which creates an opportunity for malicious input to be incorporated into the final artifact.\n - Ingestion points: User-provided specifications for the frontend artifact's components and behavior as described in
SKILL.md.\n - Boundary markers: None specified in the workflow to isolate user-provided requirements from the resulting code generation.\n
- Capability inventory: Shell scripts that write to the local filesystem, install software packages, and execute build toolchains.\n
- Sanitization: The skill lacks explicit sanitization or validation logic; security depends on the agent's ability to safely translate instructions into code.
Audit Metadata