skills/shipshitdev/skills/scaffold/Gen Agent Trust Hub

scaffold

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the execution of the vendor's package @shipshitdev/v0 via npx for full project scaffolding.
  • [REMOTE_CODE_EXECUTION]: Utilizes npx to download and run the @shipshitdev/v0 tool, which executes remote code locally.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and replicates patterns from existing codebase files, which could contain malicious instructions.
  • Ingestion points: Local source files within the repository used as examples for scaffolding (SKILL.md).
  • Boundary markers: Absent; the skill lacks delimiters or warnings to ignore instructions embedded in the analyzed code.
  • Capability inventory: Broad file system write access for creating and modifying local source and configuration files.
  • Sanitization: No sanitization or pattern validation is specified for the ingested examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:59 AM
Security Audit — agent-trust-hub — scaffold