landing-page-vercel
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied product information to generate landing page content, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill accepts untrusted data through the 'PRD Brief Intake' phase in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters for separating user input from system instructions.
- Capability inventory: The skill writes files to the local system using scripts/scaffold.py and executes deployment commands (npx vercel).
- Sanitization: The generated script.js uses .textContent to safely render data in the DOM, which effectively mitigates the risk of executing malicious scripts embedded in the user input.
- [COMMAND_EXECUTION]: The skill uses shell commands to perform scaffolding and deployment tasks.
- SKILL.md instructs the agent to run python3 scripts/scaffold.py for project generation.
- The skill provides instructions for one-click deployment using npx vercel and bunx vercel.
- [EXTERNAL_DOWNLOADS]: The skill references external scripts and tools from well-known services and vendor repositories.
- Mentions npx @shipshitdev/v0, which is a package provided by the skill's author.
- References analytics scripts from Plausible (plausible.io) and Fathom (cdn.usefathom.com).
- Uses the Vercel CLI via npx and bunx for production deployments.
Audit Metadata