saas-code-generator

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts (scaffold.sh and generate-env.sh) to automate project setup. These scripts include robust security controls, such as project name validation via regular expressions to prevent command injection and checks for path traversal sequences (..).- [EXTERNAL_DOWNLOADS]: The skill references official package registries (NPM, PyPI, and Go) to install standard, well-known frameworks like Next.js, FastAPI, and Express. The dependencies are pinned or use standard versioning ranges from reputable sources.- [PROMPT_INJECTION]: As a code generator that ingests user blueprints, the skill has an attack surface for indirect prompt injection. This is effectively mitigated by the skill's operational flow, which requires the agent to present a 'Generation Plan' for user review and approval before writing any code to the filesystem.- [CREDENTIALS_UNSAFE]: The generate-env.sh script is designed to generate new, cryptographically secure random secrets for local development using openssl or Python's secrets module. It enforces restrictive file permissions (chmod 600) on the resulting .env files to ensure they are only accessible by the owner.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 04:51 AM