skills/wix/skills/wix-docs-base44/Gen Agent Trust Hub

wix-docs-base44

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The bootstrap.md file contains a script that uses child_process.execSync to run npx skills add. This is used to install the skill and its dependencies into the environment, which is a significant privilege in a sandbox environment.
  • [REMOTE_CODE_EXECUTION]: In SKILL.md, the instructions tell the agent to load the docs.js module using the new Function constructor. This pattern is used to dynamically execute code read from the file system, which is a form of dynamic code generation and execution.
  • [EXTERNAL_DOWNLOADS]: The skill's functions (browse, search, fetchDoc, callApi, and specQuery) perform network requests to various wixapis.com and wix.com domains to fetch documentation and interact with APIs. These are documented as the primary purpose of the skill for the vendor 'wix'.
  • [COMMAND_EXECUTION]: The specQuery function in scripts/docs.js sends arbitrary JavaScript code strings to a remote endpoint (https://mcp.wix.com/api/code-mode/search) for execution. While the execution happens on a remote server managed by the vendor, the pattern involves sending and executing code dynamically.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 03:11 PM
Security Audit — agent-trust-hub — wix-docs-base44