scaffold-frontend-project
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch a standard Node.js.gitignorefile from GitHub's official repository (github.com/github/gitignore). As this targets a well-known and trusted organization, the operation is considered safe. - [COMMAND_EXECUTION]: The skill instructs the agent to execute several shell commands to initialize the project, including
pnpm dlx,pnpm install, andprek install. These are standard project initialization steps. The use ofgh workflow runfor triggering releases is also a standard development practice. - [INDIRECT_PROMPT_INJECTION]: The skill defines a scaffolding process that ingests user-provided information such as project names and descriptions and interpolates them into file templates. While this is a common vector for indirect prompt injection, it is the primary and intended function of a scaffolding skill and is managed within the agent's controlled environment.
- Ingestion points: Discovery phase questions (Project name, Description, GitHub repo) in
SKILL.mdused for template substitution. - Boundary markers: Absent; user strings are interpolated directly into placeholders within templates found in
REFERENCE.md. - Capability inventory: Shell command execution (
pnpm,prek,just,curl) and file system write operations as specified in the scaffolding workflow inSKILL.md. - Sanitization: Absent; the skill relies on direct substitution of user-provided strings into designated placeholders.
Audit Metadata