page-template
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
site.shscript executessshandrsynccommands to synchronize the generated site content to a remote host. These operations are essential to the skill's purpose as a deployment tool and require manual configuration of remote host details by the user. - [PERSISTENCE]: The
install.shscript provides an optional--hookflag that installs a gitpre-pushhook. This hook automatically triggers the site's navigation rebuild and remote synchronization whenever the user performs agit pushto the main branch. While this represents a persistent execution trigger tied to repository actions, it is a documented deployment feature. - [INDIRECT_PROMPT_INJECTION]: The
build-nav.pyscript possesses an indirect prompt injection surface as it ingests untrusted data from the filesystem. - Ingestion points: The script recursively walks the site directory and reads the
<title>and<h1>tags from every*.htmlfile to generate labels for the navigation rail. - Boundary markers: The generated navigation content is injected into every page between explicit
<!-- AUTO-NAV-START -->and<!-- AUTO-NAV-END -->comment markers. - Capability inventory: The skill has the capability to write to the local filesystem and perform network operations via
sshandrsyncinsite.sh. - Sanitization: The script uses
html.escape()on all extracted titles and headers before rendering them into the navigation rail, which effectively prevents XSS and other injection attacks targeting the site's structure.
Audit Metadata