svelte-code-writer
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto download and execute the@sveltejs/mcppackage from the NPM registry. This package is part of a well-known ecosystem associated with the Svelte framework. - [COMMAND_EXECUTION]: The skill executes shell commands using
npxand interpolates user-provided content (code snippets or file paths) as arguments to thesvelte-autofixertool. - Evidence:
npx @sveltejs/mcp svelte-autofixer "<code_or_path>"allows shell execution with variable input. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process Svelte components and modules, which may contain malicious instructions if the source code is from an untrusted third party.
- Ingestion points: The
svelte-autofixercommand inSKILL.mdtakes code or file paths as input for analysis. - Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" warnings defined to isolate the processed code from the agent's logic.
- Capability inventory: The skill can execute shell commands (
npx) and read local files. - Sanitization: The instructions recommend manual escaping of the
$character (\$) to prevent shell variable substitution, but no automated sanitization or validation of the code content itself is present.
Audit Metadata