scaffold-frontend-project
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a standard Node.js .gitignore template directly from the official GitHub
github/gitignorerepository. This is a common and safe practice for project scaffolding. - [COMMAND_EXECUTION]: The skill executes
pnpm dlx create-tsrouter-app@latestandpnpm dlx shadcn@latestto bootstrap the project. These are standard CLI tools for the Vite/React ecosystem. - [REMOTE_CODE_EXECUTION]: While the skill downloads a file from GitHub, it is a static
.gitignorefile and is not executed as code. The automated scan's warning is a false positive based on the use ofcurland a configuration file path. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user input (project name, description) and interpolates it into template files. While this is an ingestion surface, it is constrained to boilerplate scaffolding and does not expose sensitive capabilities to the processed data.
Audit Metadata