migrate-to-shoehorn

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain any malicious patterns, obfuscation, or unauthorized data access. It serves a legitimate purpose of helping developers refactor their test code by providing clear migration examples.\n- [EXTERNAL_DOWNLOADS]: Recommends the installation of the @total-typescript/shoehorn package from the official npm registry, which is a standard procedure for utilizing third-party libraries in a JavaScript/TypeScript project.\n- [COMMAND_EXECUTION]: Provides a grep shell command to assist the user in locating relevant test files within their local filesystem for migration.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to process and refactor user-provided test files.\n
  • Ingestion points: Local project test files (*.test.ts, *.spec.ts) identified via grep (SKILL.md).\n
  • Boundary markers: None identified in the instructions.\n
  • Capability inventory: Execution of shell commands and installation of node packages (SKILL.md).\n
  • Sanitization: None performed on the file content being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — migrate-to-shoehorn