typescript-expert

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The diagnostic script scripts/ts_diagnostic.py utilizes subprocess.run() with shell=True. This is a dangerous coding pattern that facilitates shell injection vulnerabilities if command strings incorporate untrusted inputs. While current usage involves hardcoded strings like npx tsc --version, the technique is fundamentally insecure for skill-based automation.
  • [PROMPT_INJECTION]: The skill has a significant surface area for indirect prompt injection. It is designed to proactively ingest and parse data from external project files, including package.json, tsconfig.json, and source code in the src/ directory. Maliciously crafted content in these files could attempt to override the agent's instructions, especially given the skill's capabilities for executing follow-up shell commands.
  • [COMMAND_EXECUTION]: The SKILL.md file instructs the agent to execute various shell commands using node -e and npx utilities for environment discovery. While these are common in developer environments, they grant the agent high-privilege execution capabilities that depend on the integrity of the local file system and project configuration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — typescript-expert