build-lab
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The loader template provided in
references/nextjs-scaffold.mdimplements dynamicimport()to loadmeta.tsmodules based on directory names discovered viafs.readdirSync. This pattern facilitates the execution of local files based on the filesystem structure.\n- [INDIRECT_PROMPT_INJECTION]: The registry system implements a data ingestion surface where metadata from local files influences the agent's context during future sessions. 1. Ingestion points: TheloadLabEntriesfunction inreferences/nextjs-scaffold.mddiscovers and imports metadata modules from subfolders. 2. Boundary markers: The instructions do not define specific delimiters or safety warnings for the imported metadata content. 3. Capability inventory: The ingested metadata is used to build the agent's understanding of available labs via theAGENTS.md/CLAUDE.mdsection. 4. Sanitization: There is no evidence of validation or filtering of the metadata fields before they are processed by the agent.\n- [COMMAND_EXECUTION]: TheSetupinstructions inSKILL.mdrequire the agent to executegit mvshell commands to migrate existing project files as part of the initial configuration.
Audit Metadata