artifacts-builder

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts init-artifact.sh and bundle-artifact.sh download and install standard frontend development packages from the NPM registry, including Vite, Tailwind CSS, Parcel, and the vendor-owned UI library @agenticindiedev/ui.- [COMMAND_EXECUTION]: The scripts/init-artifact.sh script incorporates the user-supplied project name directly into shell command strings and sed expressions. This creates an injection point where a malicious project name could execute arbitrary commands or manipulate the filesystem beyond the intended project directory.- [PRIVILEGE_ESCALATION]: The project initialization script attempts a global installation of the pnpm package manager (npm install -g pnpm). This modifies the persistent system environment and often requires administrative privileges, which is an overreach for local project setup.- [INDIRECT_PROMPT_INJECTION]: The skill processes external input to generate and build code artifacts.
  • Ingestion points: Project name argument in scripts/init-artifact.sh and the React source code generated by the agent.
  • Boundary markers: Absent; there are no delimiters or instructions to ignore embedded commands in the processed data.
  • Capability inventory: File system writes, sed modifications, and package installation/execution.
  • Sanitization: Absent; the project name is used without validation or escaping in shell contexts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — artifacts-builder