node-cli-script
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The workflow involves making scripts executable with
chmod +xand running them usingnode script.js. These actions are necessary for the skill's primary purpose of building and testing CLI tools.\n- [PROMPT_INJECTION]: The skill interprets user instructions to generate scripts, which creates a potential surface for indirect prompt injection. However, this is inherent to its function as a developer tool and is mitigated by the emphasis on using standard, audited Node.js built-ins.\n - Ingestion points: User requests for CLI tools, scripts, or automation tasks defined in
SKILL.md.\n - Boundary markers: None; the skill does not implement specific delimiters for user-provided data.\n
- Capability inventory: Generated scripts can interact with the file system (
node:fs), make network requests (fetch), and access environment variables.\n - Sanitization: The skill does not provide explicit sanitization logic, relying on the underlying agent's safety guardrails.
Audit Metadata