node-native-build
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script 'scripts/check-node-toolchain.sh' executes several standard system commands to gather version and path information, including 'node -v', 'npm -v', 'python3', 'make', 'clang', 'cc', and 'pkg-config'. The skill also facilitates 'npm install' and other package manager operations to resolve build errors.
- [DYNAMIC_EXECUTION]: The diagnostic script utilizes 'node -p' to dynamically evaluate a JavaScript expression ('process.platform + " " + process.arch') for architecture detection. This is a common and low-risk method for environment verification in Node.js development tools.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external build error logs and node-gyp output to determine appropriate fixes, creating a vulnerability surface where malicious output from a compromised build process could influence agent behavior.
- Ingestion points: Build error logs, gyp ERR! messages, and binding.gyp output processed during troubleshooting (SKILL.md).
- Boundary markers: None identified; build output is processed as raw text.
- Capability inventory: File system writes (creating ~/.gyp/include.gypi), environment variable modification (GYP_DEFINES, NODE_OPTIONS), and package manager execution (npm, yarn, pnpm).
- Sanitization: None identified for the processed error messages.
Audit Metadata