migrate-to-shoehorn
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill does not contain any malicious patterns, obfuscation, or unauthorized data access. It serves a legitimate purpose of helping developers refactor their test code by providing clear migration examples.\n- [EXTERNAL_DOWNLOADS]: Recommends the installation of the
@total-typescript/shoehornpackage from the official npm registry, which is a standard procedure for utilizing third-party libraries in a JavaScript/TypeScript project.\n- [COMMAND_EXECUTION]: Provides agrepshell command to assist the user in locating relevant test files within their local filesystem for migration.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to process and refactor user-provided test files.\n - Ingestion points: Local project test files (
*.test.ts,*.spec.ts) identified viagrep(SKILL.md).\n - Boundary markers: None identified in the instructions.\n
- Capability inventory: Execution of shell commands and installation of node packages (SKILL.md).\n
- Sanitization: None performed on the file content being processed.
Audit Metadata