typescript-expert
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The diagnostic script
scripts/ts_diagnostic.pyutilizessubprocess.run()withshell=True. This is a dangerous coding pattern that facilitates shell injection vulnerabilities if command strings incorporate untrusted inputs. While current usage involves hardcoded strings likenpx tsc --version, the technique is fundamentally insecure for skill-based automation. - [PROMPT_INJECTION]: The skill has a significant surface area for indirect prompt injection. It is designed to proactively ingest and parse data from external project files, including
package.json,tsconfig.json, and source code in thesrc/directory. Maliciously crafted content in these files could attempt to override the agent's instructions, especially given the skill's capabilities for executing follow-up shell commands. - [COMMAND_EXECUTION]: The
SKILL.mdfile instructs the agent to execute various shell commands usingnode -eandnpxutilities for environment discovery. While these are common in developer environments, they grant the agent high-privilege execution capabilities that depend on the integrity of the local file system and project configuration.
Audit Metadata