create-element
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (INFO): The skill provides structural documentation and a local utility script for component development. No malicious behaviors were identified.\n- [Dynamic Execution] (LOW): The
scaffold-element.tsscript generates boilerplate code from hardcoded templates. This is a common pattern for scaffolding tools and does not involve untrusted input execution or remote downloads.\n- [Indirect Prompt Injection] (LOW): The scaffolding utility constructs file paths using command-line arguments without path traversal sanitization. While this is a minor security weakness for a CLI tool, it does not constitute a malicious AI agent attack vector in this context.
Audit Metadata