javascript-pro

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as eslint --fix for linting and jest for running unit tests as part of the validation and testing steps of its core workflow.\n- [COMMAND_EXECUTION]: The references/node-essentials.md file provides code examples for using the Node.js child_process module, including exec and spawn, to interact with the host operating system.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data including project requirements, package.json configurations, and source code files, which serves as an ingestion point for potentially untrusted content that could influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — javascript-pro