bestax-migrate
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
bestax-migrateutility usingpnpm dlx. This involves downloading and executing a tool from a public registry. Since this is a vendor-owned resource ('bestax-migrate' from the author 'allxsmith') and is central to the skill's stated purpose of code migration, it is considered a legitimate operation. - [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading and acting upon content from the local codebase being migrated, which presents a surface for indirect instructions to influence the agent.
- Ingestion points: The agent is directed to read all files in the
src/directory and specifically search forTODO(bestax-migrate)comments to guide its subsequent actions in the migration process. - Boundary markers: The instructions do not implement specific delimiters or safety warnings to distinguish between original code content and potentially malicious instructions embedded in comments.
- Capability inventory: The skill provides the agent with the ability to execute shell commands (
pnpm,npm,grep) and perform file system modifications. - Sanitization: There is no evidence of sanitization or validation performed on the code or comments before they are processed by the agent's logic.
Audit Metadata