node
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends and provides implementation examples for several industry-standard Node.js libraries, including
pino(logging),zod(validation),piscina(worker pools), and@platformatic/flame(profiling). These resources are well-established within the Node.js ecosystem and are used for enhancing application reliability and performance. - [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for building data ingestion pipelines (e.g., CSV and ETL processing using streams). This identifies a potential surface for indirect prompt injection if the agent is tasked with processing untrusted data using these documented techniques.
- Ingestion points: Examples in
rules/streams.mddemonstrate the use ofcreateReadStreamto ingest data from external files such asusers.csv. - Capability inventory: The documentation covers standard Node.js capabilities including file system access, network requests, and stream-based data transformation.
- Boundary markers: The provided code examples focus on parsing logic and do not explicitly include delimiters or instructions for the agent to ignore embedded commands within the processed data.
- Sanitization: Input sanitization specific to avoiding prompt injection is not discussed in the data processing implementation patterns.
Audit Metadata