scaffold
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the execution of the vendor's package
@shipshitdev/v0vianpxfor full project scaffolding. - [REMOTE_CODE_EXECUTION]: Utilizes
npxto download and run the@shipshitdev/v0tool, which executes remote code locally. - [INDIRECT_PROMPT_INJECTION]: The skill identifies and replicates patterns from existing codebase files, which could contain malicious instructions.
- Ingestion points: Local source files within the repository used as examples for scaffolding (SKILL.md).
- Boundary markers: Absent; the skill lacks delimiters or warnings to ignore instructions embedded in the analyzed code.
- Capability inventory: Broad file system write access for creating and modifying local source and configuration files.
- Sanitization: No sanitization or pattern validation is specified for the ingested examples.
Audit Metadata