apexbank-analytics-dashboard
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions direct the agent or user to clone a repository from an external source (
github.com/fhuber82/apexbank-analytics-hub.git) which is not identified as a trusted vendor. - [COMMAND_EXECUTION]: The skill instructs the execution of shell commands to set up the environment, including
git cloneand starting local web servers using Python (python -m http.server) or Node.js (npx http-server). - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection via untrusted data processing. It ingests data from
localStorageand user-submitted forms to render dashboard elements. - Ingestion points: Data is loaded from
localStorageinAccountManager,TransactionManager, andSavingsGoalManager, as well as from HTML forms viaFormDatainTransferManagerandMortgageCalculator. - Boundary markers: No boundary markers or instructions to ignore embedded commands are present when processing external data.
- Capability inventory: The skill possesses the capability to write to the DOM (
innerHTML) and trigger downloads (Blob/URL.createObjectURL). - Sanitization: There is no evidence of sanitization or escaping of external content before it is interpolated into the DOM.
- [DYNAMIC_EXECUTION]: The JavaScript code snippets provided in
SKILL.mduse.innerHTMLto render data fromaccount.name,txn.description, andgoal.name. This pattern is vulnerable to Cross-Site Scripting (XSS) if the data source (e.g., a transaction description) contains malicious script tags.
Audit Metadata