angular-developer

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to interpolate user-provided inputs—such as project names, component names, and version strings—directly into shell commands like ng new and npx @angular/cli. This represents a standard surface for indirect prompt injection if the agent does not manually validate these identifiers.
  • Ingestion points: User prompts for project names, component paths, and specific Angular versions in SKILL.md and references/cli.md.
  • Boundary markers: Absent; the instructions do not explicitly provide delimiters or warnings to the agent to escape or sanitize user-provided strings before they are passed to the terminal.
  • Capability inventory: The skill leverages extensive command execution capabilities (ng build, ng new, ng generate, ng serve, npx) and broad file system write access for code generation across all reference files.
  • Sanitization: Absent; no specific escaping, validation, or filtering logic is recommended for user-provided identifiers before they are used in CLI command strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 05:11 PM