node-cli-script
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow includes steps to make generated scripts executable via
chmod +xand subsequently run them using the Node.js runtime. This is standard for CLI development but constitutes dynamic execution of potentially untrusted logic generated from user prompts. - [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection as it processes user-provided requirements to generate and execute shell commands and Node.js scripts.
- Ingestion points: User requests describing CLI tools or automation tasks defined in SKILL.md.
- Boundary markers: Absent; the skill does not define specific delimiters or instructions to prevent the agent from obeying instructions embedded in the user's task description during code generation.
- Capability inventory: File system access (
node:fs), network operations (fetch), and shell command execution (chmod,node) are available to the generated scripts. - Sanitization: The instructions do not prescribe validation or sanitization of user input before it is incorporated into the generated script or executed.
Audit Metadata