rp-execute-setup
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes configuration and requirement data from
setup-requirements.mdto automate environment provisioning, introducing an indirect prompt injection surface. - Ingestion points: Reads and interprets migration requirements from
migrations/<project>/setup-requirements.md. - Boundary markers: No explicit delimiters or boundary instructions are defined to separate untrusted data from the agent's internal logic.
- Capability inventory: The agent has the capability to perform site-wide administrative actions via
CallWixSiteAPI, including installing Wix apps and creating database collections. - Sanitization: Lacks formal input validation or sanitization logic for the data extracted from the requirement artifacts.
Audit Metadata