interactive-component-creator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behavior or security vulnerabilities were detected in the skill instructions or associated scripts. The functionality is consistent with its stated purpose of building web artifacts.
- [COMMAND_EXECUTION]: The skill utilizes shell scripts (
scripts/init-artifact.shandscripts/bundle-artifact.sh) to automate project setup and asset bundling. These scripts perform routine development tasks such as project scaffolding, cleaning build directories, and creating configuration files. - [EXTERNAL_DOWNLOADS]: The scripts download and install standard, reputable frontend development dependencies and tools (including Vite, Tailwind CSS, Parcel, and Radix UI components) from the public NPM registry using
pnpm. These are well-known services and do not pose a security risk in this context. - [INDIRECT_PROMPT_INJECTION]: As the skill generates web components based on user descriptions, it ingests external data that influences code generation. This represents the primary surface for potential prompt injection, though it is the intended primary purpose of the skill and falls within the expected operational scope of a UI-generation tool.
Audit Metadata