install-anti-slop
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified during the analysis of the skill's instructions, installation scripts, or linter rule implementations.
- [COMMAND_EXECUTION]: The skill executes a local installation script (
scripts/install.mjs) to vendor the plugin code and utilizes standard package managers (npm, yarn, or pnpm) to install development dependencies. These operations are transparent and restricted to the repository context. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install
oxlintand@oxlint/pluginsfrom official public registries. These are well-known, established tools in the JavaScript/TypeScript development ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository configuration and source code to apply linting rules. While it ingests external data (project files), it does so via static analysis that does not influence the agent's core instruction flow or bypass safety guardrails.
Audit Metadata