saas-code-generator
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell scripts (
scaffold.shandgenerate-env.sh) to automate project setup. These scripts include robust security controls, such as project name validation via regular expressions to prevent command injection and checks for path traversal sequences (..).- [EXTERNAL_DOWNLOADS]: The skill references official package registries (NPM, PyPI, and Go) to install standard, well-known frameworks like Next.js, FastAPI, and Express. The dependencies are pinned or use standard versioning ranges from reputable sources.- [PROMPT_INJECTION]: As a code generator that ingests user blueprints, the skill has an attack surface for indirect prompt injection. This is effectively mitigated by the skill's operational flow, which requires the agent to present a 'Generation Plan' for user review and approval before writing any code to the filesystem.- [CREDENTIALS_UNSAFE]: Thegenerate-env.shscript is designed to generate new, cryptographically secure random secrets for local development usingopensslor Python'ssecretsmodule. It enforces restrictive file permissions (chmod 600) on the resulting.envfiles to ensure they are only accessible by the owner.
Audit Metadata