site-builder

Fail

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes several third-party packages from the npm registry using npx (e.g., nanobanana-mcp, agentation-mcp). These resources are not from established trusted vendors or well-known service providers.\n- [REMOTE_CODE_EXECUTION]: The workflow involves installing an external agent skill (nextlevelbuilder/ui-ux-pro-max-skill) at the project level. This results in the execution of unverified remote code within the agent's environment.\n- [COMMAND_EXECUTION]: The skill establishes persistence by installing a custom script (reference/doc-refresh-script.sh) into the project's git pre-commit hooks (.git/hooks/pre-commit). This script automatically executes on the host machine during every git commit operation. Additionally, the skill automatically modifies the Claude Code project configuration (.claude/settings.json) to grant permissions to various MCP tools, which reduces user oversight for sensitive operations like pull request management.\n- [PROMPT_INJECTION]: The skill processes untrusted data from business analysis and competitor research, which is then passed to multiple specialist agents with significant capabilities (bash access, PR creation, deployment). The skill lacks explicit instructions for these agents to ignore potentially malicious instructions embedded in the ingested data. While the use of human approval gates provides a layer of mitigation, the vulnerability surface for indirect prompt injection remains present.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — site-builder