scaffold-frontend-project

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a standard Node.js .gitignore template directly from the official GitHub github/gitignore repository. This is a common and safe practice for project scaffolding.
  • [COMMAND_EXECUTION]: The skill executes pnpm dlx create-tsrouter-app@latest and pnpm dlx shadcn@latest to bootstrap the project. These are standard CLI tools for the Vite/React ecosystem.
  • [REMOTE_CODE_EXECUTION]: While the skill downloads a file from GitHub, it is a static .gitignore file and is not executed as code. The automated scan's warning is a false positive based on the use of curl and a configuration file path.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input (project name, description) and interpolates it into template files. While this is an ingestion surface, it is constrained to boilerplate scaffolding and does not expose sensitive capabilities to the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:54 PM
Security Audit — agent-trust-hub — scaffold-frontend-project