fullstack-workspace-init

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's instructions in SKILL.md direct the agent to take a user-provided "Product scope or PRD-style brief" and pass it directly to a shell command as the --scope argument for npx @shipshitdev/v0.
  • Ingestion points: The product brief input defined in the skill contract in SKILL.md.
  • Boundary markers: Absent. While the command template uses double quotes (--scope "<product scope>"), these can be bypassed by user input containing malicious shell characters or escaped quotes.
  • Capability inventory: The skill has the capability to execute shell commands via npx and write a significant number of files to the filesystem.
  • Sanitization: Absent. There are no instructions for the agent to sanitize or validate the user-provided brief before interpolation into the command line.
  • [COMMAND_EXECUTION]: The Python script scripts/init-workspace.py uses subprocess.run to execute an initialization script located at ~/.codex/skills/agent-folder-init/scripts/scaffold.py. This is part of the intended integration with the agent platform's internal skill management system.
  • [REMOTE_CODE_EXECUTION]: The skill uses npx @shipshitdev/v0 to scaffold projects. This command downloads and executes a package from the NPM registry. This is a vendor-owned resource associated with the skill's author context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — fullstack-workspace-init