backend-setup-wizard

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation and search results, which are identified as ingestion points for untrusted data. It includes strong boundary instructions requiring the agent to treat fetched content as reference material only and to explicitly ignore any embedded directives or instructions intended to override agent behavior. This effectively mitigates the risk of instructions embedded in third-party documentation being followed.
  • [COMMAND_EXECUTION]: The skill interacts with the user's terminal to execute official provider CLIs (such as Stripe, Vercel, and Supabase). It enforces strict validation rules, requiring domain-matching for any installation scripts and the use of official package registries to prevent the execution of malicious or unofficial code.
  • [CREDENTIALS_SAFE]: The skill implements a zero-knowledge credential handling model. It prioritizes OAuth/CLI login flows performed by the user and provides masked shell commands for the user to run in their own terminal when populating .env files. The agent is explicitly prohibited from reading raw credentials back from the environment or chat history, and uses silent checks (e.g., grep -q) to verify the presence of configuration without exposing the contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:02 PM
Security Audit — agent-trust-hub — backend-setup-wizard