Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 6. **Plan, then stop.** `node --import tsx evals/contract.mjs && npm run check && cargo-ai cdk plan`,
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed website-building recipe for Cargo with meaningful deploy and DNS power, but it consistently requires review and explicit approval before high-impact actions.
Install only in a Cargo workspace where you are comfortable letting an agent prepare website, hosting, and DNS changes. Review the generated pull request and cargo-ai cdk plan carefully, especially any DNS zone replacement, mailbox impact, deploy, or domain purchase line. Consider pinning @cargo-ai/cli and shadcn versions if your environment requires reproducible installs.
Referenced artifact was not completely inspected
6. **Plan, then stop.** `node --import tsx evals/contract.mjs && npm run check && cargo-ai cdk plan`,
Referenced artifact was not completely inspected
6. **Plan, then stop.** `node --import tsx evals/contract.mjs && npm run check && cargo-ai cdk plan`,
Referenced artifact was not completely inspected
6. **Plan, then stop.** `node --import tsx evals/contract.mjs && npm run check && cargo-ai cdk plan`,
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
"scripts": {
"dev": "next dev --hostname 127.0.0.1",
"check": "tsc --noEmit",
"build": "next build && rm -rf dist && mv out dist"
},
"dependencies": {
"class-variance-authority": "0.7.1",
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**Derive before you ask.** An input with a lookup is looked up, not asked.
| Input | Kind | How it is answered | Why it matters |
| ---------------------------------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| company, audience, offering, proof | value | **derived**: `context/` and the existing site or brand guide; ask only for what is missing | The pages say only what the company approved. Placeholder copy and invented proof never ship. |
| pages, call to action, design direction | asked | propose a brief from the context and let the operator correct it | The brief is the scope every later pull request is reviewed against. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**Derive before you ask.** An input with a lookup is looked up, not asked.
| Input | Kind | How it is answered | Why it matters |
| ---------------------------------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| company, audience, offering, proof | value | **derived**: `context/` and the existing site or brand guide; ask only for what is missing | The pages say only what the company approved. Placeholder copy and invented proof never ship. |
| pages, call to action, design direction | asked | propose a brief from the context and let the operator correct it | The brief is the scope every later pull request is reviewed against. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.
| Variation | When it is right | How | What it costs |
| ------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| `external-dns` | The domain's DNS is at another provider, as for most existing company domains | Delete `infra/domains/website.ts`, keep `domains` on the app, add the records at the provider after the first deploy ([domain](references/domain.md)) | Three records and an apex redirect kept by hand; Cargo cannot correct them. |
| `register-domain` | The company wants a new domain for the website, bought through Cargo | Drop `adopt: true` in `infra/domains/website.ts` and the contract's adopt assertion | Workspace credits, not refundable; the plan's `+ create domain:…` line is the purchase. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.
| Variation | When it is right | How | What it costs |
| ------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| `external-dns` | The domain's DNS is at another provider, as for most existing company domains | Delete `infra/domains/website.ts`, keep `domains` on the app, add the records at the provider after the first deploy ([domain](references/domain.md)) | Three records and an apex redirect kept by hand; Cargo cannot correct them. |
| `register-domain` | The company wants a new domain for the website, bought through Cargo | Drop `adopt: true` in `infra/domains/website.ts` and the contract's adopt assertion | Workspace credits, not refundable; the plan's `+ create domain:…` line is the purchase. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| `source-recreation` | An authorized repository or live site already exists | Port its pages and assets into the app, keeping attribution ([build and review](references/build-and-review.md#recreate-an-existing-site)) | Dependency migration, inherited defects to separate from new ones, binary assets to adapt for a text upload. |
| `redesign` | The current site does not fit the company it describes | Approve new tokens, structure and copy instead of matching the old pages | More design decisions, and no old page to compare against. |
| `more-pages` | The brief needs pricing, landing or legal pages | `app/<route>/page.tsx` with `pageMetadata`, plus the route in `app/sitemap.ts` | Metadata and sitemap to keep current per page. |
| `working-form` | A demo or contact form has to deliver | Post it to an approved destination and test a real submission | A backend outside this static app, with its own consent and cost. |
## What should not change
The instruction to run npx shadcn@latest add <name> pulls and executes the latest package version at runtime rather than a pinned, reviewed version. In a code-generation workflow, this increases supply-chain risk because a compromised upstream release or unexpected breaking change could execute unreviewed code on the developer machine and alter generated source committed into the repository.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Read the records. cargo-ai hosting app list gives the app's UUID, then:
curl "https://api.getcargo.io/v1/hosting/custom-domains/list?appUuid=<app-uuid>" \
-H "authorization: Bearer $CARGO_API_TOKEN"
No suspicious patterns detected.