ESLint Custom Rule Builder
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill references and utilizes well-known, reputable packages from the ESLint ecosystem, including
eslint,espree,eslint-scope, andtypescript-eslintfor its core functionality.- [COMMAND_EXECUTION]: Documentation includes standard installation commands usingnpxand theclawhubpackage manager for environment setup.- [DATA_EXPOSURE]: Analysis confirms there are no attempts to access sensitive system files, environment variables, or hardcoded credentials.- [REMOTE_CODE_EXECUTION]: No patterns of downloading and executing arbitrary remote scripts were detected; code generation and testing are performed locally as part of the primary skill purpose.- [INDIRECT_PROMPT_INJECTION]: While the skill processes natural language descriptions to generate code (an injection surface), this is the primary intended behavior and there is no evidence of exploitable capabilities or missing sanitization that would elevate the risk.
Audit Metadata