svelte-code-writer

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and execute the @sveltejs/mcp package from the NPM registry. This package is part of a well-known ecosystem associated with the Svelte framework.
  • [COMMAND_EXECUTION]: The skill executes shell commands using npx and interpolates user-provided content (code snippets or file paths) as arguments to the svelte-autofixer tool.
  • Evidence: npx @sveltejs/mcp svelte-autofixer "<code_or_path>" allows shell execution with variable input.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process Svelte components and modules, which may contain malicious instructions if the source code is from an untrusted third party.
  • Ingestion points: The svelte-autofixer command in SKILL.md takes code or file paths as input for analysis.
  • Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" warnings defined to isolate the processed code from the agent's logic.
  • Capability inventory: The skill can execute shell commands (npx) and read local files.
  • Sanitization: The instructions recommend manual escaping of the $ character (\$) to prevent shell variable substitution, but no automated sanitization or validation of the code content itself is present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — svelte-code-writer