project-builder

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the bash tool to execute and verify generated Python scripts and project components during the build and debug phases.\n- [EXTERNAL_DOWNLOADS]: The skill integrates with well-known CDNs like jsDelivr and d3js.org for frontend visualization libraries and uses the OpenRouter API for text processing, with all external traffic routed through a platform-standard proxy service.\n- [PROMPT_INJECTION]: The skill processes user intent to generate code, creating an indirect prompt injection surface; it mitigates this by providing a template pattern that separates raw data from LLM-generated analysis to prevent data hallucinations or manipulation.\n- [DATA_EXFILTRATION]: The skill handles project configuration and environment variables, including explicit instructions to use .gitignore to exclude sensitive files such as .env and private keys from being published or shared.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:37 AM