wix-headless-cold-start

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Downloads and executes a bootstrap script (bootstrap.mjs) from the vendor's official domain (wix.com) to initialize the Wix CLI and handle authentication.
  • [EXTERNAL_DOWNLOADS]: Installs the wix/skills package and associated components (wix-headless-kit, wix-docs, wix-manage) from an external registry using npx skills@latest.
  • [COMMAND_EXECUTION]: Runs various system and environment setup commands, including node, npx, and package managers like brew or winget for dependency management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project files (such as ZIP archives or URLs) provided by the user in the initial brief, creating an ingestion point for potentially untrusted data. * Ingestion points: Project files or URLs provided in the user brief are extracted directly into the local project directory (headless-kit.md, headless.md). * Boundary markers: Absent. There are no explicit instructions or delimiters to prevent the agent from following directions contained within these external files. * Capability inventory: The skill utilizes shell command execution (node, npx), file system operations (extracting archives), and network operations (curl, iwr) in headless-kit.md and headless.md. * Sanitization: Absent. The skill does not perform validation or sanitization of the content within the extracted project files before handing off the execution to subsequent stages.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 10:43 AM
Security Audit — agent-trust-hub — wix-headless-cold-start