wix-docs-base44
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
bootstrap.mdfile contains a script that useschild_process.execSyncto runnpx skills add. This is used to install the skill and its dependencies into the environment, which is a significant privilege in a sandbox environment. - [REMOTE_CODE_EXECUTION]: In
SKILL.md, the instructions tell the agent to load thedocs.jsmodule using thenew Functionconstructor. This pattern is used to dynamically execute code read from the file system, which is a form of dynamic code generation and execution. - [EXTERNAL_DOWNLOADS]: The skill's functions (
browse,search,fetchDoc,callApi, andspecQuery) perform network requests to variouswixapis.comandwix.comdomains to fetch documentation and interact with APIs. These are documented as the primary purpose of the skill for the vendor 'wix'. - [COMMAND_EXECUTION]: The
specQueryfunction inscripts/docs.jssends arbitrary JavaScript code strings to a remote endpoint (https://mcp.wix.com/api/code-mode/search) for execution. While the execution happens on a remote server managed by the vendor, the pattern involves sending and executing code dynamically.
Audit Metadata