effect-ts
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for cloning the official Effect source code repository from
https://github.com/Effect-TS/effectinto a local directory for reference purposes. It also guides the installation ofeffect@betaand other@effect/*packages from standard package registries. These sources are well-known and professional repositories for the Effect ecosystem. - [COMMAND_EXECUTION]: The skill contains setup instructions that involve creating and running a shell script (
scripts/prepare-effect.sh) to automate thegit cloneprocess. It also guides the execution of package management commands likenpm install. These are standard developer tasks for project initialization and dependency management. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external code, specifically the source code of the Effect library located in
./.repos/effectand the user's own repository. This creates a surface where instructions embedded in external code (e.g., in comments or documentation) could potentially influence agent behavior, a common characteristic of development-focused skills. - Ingestion points: Effect library source code (
./.repos/effect/packages/effect/src/) and user-provided code files. - Boundary markers: No specific boundary markers are defined for isolating external code content from instructions.
- Capability inventory: The skill performs package installations and git operations as part of its setup and maintenance guidance.
- Sanitization: No explicit sanitization or filtering of the analyzed code is performed before processing.
Audit Metadata