space-chart-html

Fail

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The workflow in SKILL.md instructs the agent to execute npx getdesign@latest add <slug>. This command downloads and runs code from the NPM registry at runtime, which is a high-risk pattern for remote code execution.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the getdesign package from the public NPM registry. This dependency is not from a verified or trusted vendor, increasing the risk of supply chain attacks.
  • [COMMAND_EXECUTION]: The skill uses multiple shell commands, including cd, mkdir, npx, and open. The <slug> parameter in the npx command is derived from user input, which creates a potential command injection vector if the input is not strictly validated.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted user data to generate HTML files and lacks robust sanitization.
  • Ingestion points: User-provided descriptions and style requests in SKILL.md.
  • Boundary markers: None identified; there are no instructions to ignore embedded commands within user-supplied text.
  • Capability inventory: Access to shell command execution (npx, open), file system writes, and external network downloads.
  • Sanitization: No evidence of input validation or escaping of user-provided content before it is processed or included in shell commands.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 13, 2026, 07:05 AM