node-cli-script

Pass

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflow involves making scripts executable with chmod +x and running them using node script.js. These actions are necessary for the skill's primary purpose of building and testing CLI tools.\n- [PROMPT_INJECTION]: The skill interprets user instructions to generate scripts, which creates a potential surface for indirect prompt injection. However, this is inherent to its function as a developer tool and is mitigated by the emphasis on using standard, audited Node.js built-ins.\n
  • Ingestion points: User requests for CLI tools, scripts, or automation tasks defined in SKILL.md.\n
  • Boundary markers: None; the skill does not implement specific delimiters for user-provided data.\n
  • Capability inventory: Generated scripts can interact with the file system (node:fs), make network requests (fetch), and access environment variables.\n
  • Sanitization: The skill does not provide explicit sanitization logic, relying on the underlying agent's safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 14, 2026, 11:42 AM
Security Audit — agent-trust-hub — node-cli-script