project-init-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto download and execute the@shipshitdev/v0package. This is a core part of its scaffolding functionality and originates from the skill's authoring organization. - [COMMAND_EXECUTION]: The orchestrator triggers several shell-based operations, including project initialization via
npx, dependency management viabun, and environment setup viahuskyand other delegated scripts. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Untrusted user input, such as project names, directory paths, and the 'product scope' string, is used to construct shell commands (e.g., within the
--scopeflag). - Boundary markers: There are no explicit delimiters or instructions to prevent the agent from accidentally executing malicious content that might be embedded in these user-provided inputs.
- Capability inventory: The skill possesses significant capabilities, including executing arbitrary shell commands and performing wide-ranging file system modifications across multiple orchestrated phases.
- Sanitization: The instructions do not describe any mechanisms for validating, escaping, or filtering user-provided strings before they are interpolated into terminal commands.
Audit Metadata