node-native-build

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script 'scripts/check-node-toolchain.sh' executes several standard system commands to gather version and path information, including 'node -v', 'npm -v', 'python3', 'make', 'clang', 'cc', and 'pkg-config'. The skill also facilitates 'npm install' and other package manager operations to resolve build errors.
  • [DYNAMIC_EXECUTION]: The diagnostic script utilizes 'node -p' to dynamically evaluate a JavaScript expression ('process.platform + " " + process.arch') for architecture detection. This is a common and low-risk method for environment verification in Node.js development tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external build error logs and node-gyp output to determine appropriate fixes, creating a vulnerability surface where malicious output from a compromised build process could influence agent behavior.
  • Ingestion points: Build error logs, gyp ERR! messages, and binding.gyp output processed during troubleshooting (SKILL.md).
  • Boundary markers: None identified; build output is processed as raw text.
  • Capability inventory: File system writes (creating ~/.gyp/include.gypi), environment variable modification (GYP_DEFINES, NODE_OPTIONS), and package manager execution (npm, yarn, pnpm).
  • Sanitization: None identified for the processed error messages.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:05 AM
Security Audit — agent-trust-hub — node-native-build