prototype

Warn

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute prototype code that is dynamically generated from user-supplied concept descriptions. This creates a significant risk of command injection if the input is specifically crafted to execute malicious shell commands during the testing phase.
  • [REMOTE_CODE_EXECUTION]: The core logic of the skill involves taking untrusted external descriptions and transforming them into executable scripts that are run by the agent. This pattern of script generation and subsequent execution is a major attack surface for remote code execution.
  • [DYNAMIC_EXECUTION]: The skill explicitly encourages relaxed standards and skipping error handling while generating executable code. This lowers the barrier for the creation and execution of insecure or malicious scripts at runtime.
  • [DATA_EXFILTRATION]: Since the agent has access to project files via Read/Glob tools and can execute network commands via the Bash tool, a malicious concept description could result in a prototype designed to harvest sensitive project information and exfiltrate it to a remote server.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — prototype