skills/wondelai/skills/create-app/Gen Agent Trust Hub

create-app

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a session-resume mechanism by reading existing project documentation.
  • Ingestion points: Artifacts in the docs/ folder, specifically docs/CREATE-APP-PLAN.md, are read during the 'Resume first' operating rule in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the documentation templates.
  • Capability inventory: The skill can read/write files in the docs/ directory and invoke other agent skills via their slugs.
  • Sanitization: Content read from the docs/ folder is processed without explicit sanitization or verification against a schema.
  • [EXTERNAL_DOWNLOADS]: The skill suggests the use of npx skills add wondelai/skills/<slug> --global if a specific phase-related skill is missing. This command targets the vendor's own repository and is a standard procedure for expanding the agent's capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:01 PM
Security Audit — agent-trust-hub — create-app