scaffold-frontend-project

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch a standard Node.js .gitignore file from GitHub's official repository (github.com/github/gitignore). As this targets a well-known and trusted organization, the operation is considered safe.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several shell commands to initialize the project, including pnpm dlx, pnpm install, and prek install. These are standard project initialization steps. The use of gh workflow run for triggering releases is also a standard development practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a scaffolding process that ingests user-provided information such as project names and descriptions and interpolates them into file templates. While this is a common vector for indirect prompt injection, it is the primary and intended function of a scaffolding skill and is managed within the agent's controlled environment.
  • Ingestion points: Discovery phase questions (Project name, Description, GitHub repo) in SKILL.md used for template substitution.
  • Boundary markers: Absent; user strings are interpolated directly into placeholders within templates found in REFERENCE.md.
  • Capability inventory: Shell command execution (pnpm, prek, just, curl) and file system write operations as specified in the scaffolding workflow in SKILL.md.
  • Sanitization: Absent; the skill relies on direct substitution of user-provided strings into designated placeholders.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — scaffold-frontend-project