node-cli-script

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow includes steps to make generated scripts executable via chmod +x and subsequently run them using the Node.js runtime. This is standard for CLI development but constitutes dynamic execution of potentially untrusted logic generated from user prompts.
  • [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection as it processes user-provided requirements to generate and execute shell commands and Node.js scripts.
  • Ingestion points: User requests describing CLI tools or automation tasks defined in SKILL.md.
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to prevent the agent from obeying instructions embedded in the user's task description during code generation.
  • Capability inventory: File system access (node:fs), network operations (fetch), and shell command execution (chmod, node) are available to the generated scripts.
  • Sanitization: The instructions do not prescribe validation or sanitization of user input before it is incorporated into the generated script or executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:32 AM
Security Audit — agent-trust-hub — node-cli-script