landing-page-vercel

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied product information to generate landing page content, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill accepts untrusted data through the 'PRD Brief Intake' phase in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters for separating user input from system instructions.
  • Capability inventory: The skill writes files to the local system using scripts/scaffold.py and executes deployment commands (npx vercel).
  • Sanitization: The generated script.js uses .textContent to safely render data in the DOM, which effectively mitigates the risk of executing malicious scripts embedded in the user input.
  • [COMMAND_EXECUTION]: The skill uses shell commands to perform scaffolding and deployment tasks.
  • SKILL.md instructs the agent to run python3 scripts/scaffold.py for project generation.
  • The skill provides instructions for one-click deployment using npx vercel and bunx vercel.
  • [EXTERNAL_DOWNLOADS]: The skill references external scripts and tools from well-known services and vendor repositories.
  • Mentions npx @shipshitdev/v0, which is a package provided by the skill's author.
  • References analytics scripts from Plausible (plausible.io) and Fathom (cdn.usefathom.com).
  • Uses the Vercel CLI via npx and bunx for production deployments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:30 PM
Security Audit — agent-trust-hub — landing-page-vercel