fullstack-workspace-init
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's instructions in
SKILL.mddirect the agent to take a user-provided "Product scope or PRD-style brief" and pass it directly to a shell command as the--scopeargument fornpx @shipshitdev/v0. - Ingestion points: The product brief input defined in the skill contract in
SKILL.md. - Boundary markers: Absent. While the command template uses double quotes (
--scope "<product scope>"), these can be bypassed by user input containing malicious shell characters or escaped quotes. - Capability inventory: The skill has the capability to execute shell commands via
npxand write a significant number of files to the filesystem. - Sanitization: Absent. There are no instructions for the agent to sanitize or validate the user-provided brief before interpolation into the command line.
- [COMMAND_EXECUTION]: The Python script
scripts/init-workspace.pyusessubprocess.runto execute an initialization script located at~/.codex/skills/agent-folder-init/scripts/scaffold.py. This is part of the intended integration with the agent platform's internal skill management system. - [REMOTE_CODE_EXECUTION]: The skill uses
npx @shipshitdev/v0to scaffold projects. This command downloads and executes a package from the NPM registry. This is a vendor-owned resource associated with the skill's author context.
Audit Metadata