skills/nexu-io/open-design/web-clone/Gen Agent Trust Hub

web-clone

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various local Node.js scripts to automate the cloning process. It also invokes CLI tools such as 'gh' (GitHub CLI) for repository searching and 'curl' for fetching raw content.- [EXTERNAL_DOWNLOADS]: The skill downloads website assets, including images, fonts, and source maps, from user-provided remote URLs using Playwright and the Node.js fetch API.- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests untrusted HTML, CSS, and JavaScript from external sites for agent analysis. Ingestion points: External content fetched by 'recon-site.mjs' and 'asset-harvest.mjs'. Boundary markers: 'SKILL.md' explicitly instructs the agent to treat inferred code as untrusted and verify it against raw sources. Capability inventory: The skill has filesystem write access and network communication capabilities. Sanitization: 'audit-clone.mjs' identifies tracking scripts and brand residues.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:05 AM
Security Audit — agent-trust-hub — web-clone