vite-react
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads a full project template from an external GitHub repository (
https://github.com/Eng0AI/vite-react-template.git) which is not associated with the skill author or a trusted organization. - [COMMAND_EXECUTION]: Instructions guide the agent to run
npm installandnpm run buildon the cloned files. This automatically executes scripts defined in the external repository'spackage.json(such aspostinstallor thebuildscript itself), providing a path for remote code execution from an unverified source. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing and executing code from an external source without verification.
- Ingestion points: Clones content from
https://github.com/Eng0AI/vite-react-template.gitinto the local environment. - Boundary markers: None; the agent is instructed to treat the external content as a trusted project template.
- Capability inventory: Includes shell command execution (
npm,git,vercel,netlify) and file system operations. - Sanitization: None; the skill does not validate the integrity or safety of the downloaded repository before execution.
Audit Metadata