space-chart-html
Fail
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The workflow in
SKILL.mdinstructs the agent to executenpx getdesign@latest add <slug>. This command downloads and runs code from the NPM registry at runtime, which is a high-risk pattern for remote code execution. - [EXTERNAL_DOWNLOADS]: The skill downloads the
getdesignpackage from the public NPM registry. This dependency is not from a verified or trusted vendor, increasing the risk of supply chain attacks. - [COMMAND_EXECUTION]: The skill uses multiple shell commands, including
cd,mkdir,npx, andopen. The<slug>parameter in thenpxcommand is derived from user input, which creates a potential command injection vector if the input is not strictly validated. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted user data to generate HTML files and lacks robust sanitization.
- Ingestion points: User-provided descriptions and style requests in
SKILL.md. - Boundary markers: None identified; there are no instructions to ignore embedded commands within user-supplied text.
- Capability inventory: Access to shell command execution (
npx,open), file system writes, and external network downloads. - Sanitization: No evidence of input validation or escaping of user-provided content before it is processed or included in shell commands.
Recommendations
- AI detected serious security threats
Audit Metadata