install-anti-slop

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified during the analysis of the skill's instructions, installation scripts, or linter rule implementations.
  • [COMMAND_EXECUTION]: The skill executes a local installation script (scripts/install.mjs) to vendor the plugin code and utilizes standard package managers (npm, yarn, or pnpm) to install development dependencies. These operations are transparent and restricted to the repository context.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install oxlint and @oxlint/plugins from official public registries. These are well-known, established tools in the JavaScript/TypeScript development ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository configuration and source code to apply linting rules. While it ingests external data (project files), it does so via static analysis that does not influence the agent's core instruction flow or bypass safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — install-anti-slop