project-init-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to download and execute the @shipshitdev/v0 package. This is a core part of its scaffolding functionality and originates from the skill's authoring organization.
  • [COMMAND_EXECUTION]: The orchestrator triggers several shell-based operations, including project initialization via npx, dependency management via bun, and environment setup via husky and other delegated scripts.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Untrusted user input, such as project names, directory paths, and the 'product scope' string, is used to construct shell commands (e.g., within the --scope flag).
  • Boundary markers: There are no explicit delimiters or instructions to prevent the agent from accidentally executing malicious content that might be embedded in these user-provided inputs.
  • Capability inventory: The skill possesses significant capabilities, including executing arbitrary shell commands and performing wide-ranging file system modifications across multiple orchestrated phases.
  • Sanitization: The instructions do not describe any mechanisms for validating, escaping, or filtering user-provided strings before they are interpolated into terminal commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — project-init-orchestrator