angular-modularize
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted source code from a user's local project through tools like
Read,Grep, andGlob. This creates a vulnerability where malicious instructions embedded in the source code (e.g., in comments or string literals) could potentially influence the agent's behavior. - Ingestion points: The skill explicitly instructs the agent to read
package.jsonand scan the entire project structure usingGlob("**/*.component.ts")andGrepfunctions inSKILL.md. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between the skill's instructions and the content of the data being processed.
- Capability inventory: The skill allows the agent to
EditandWriteto the file system and executeBashcommands, providing a significant impact path if an injection occurs. - Sanitization: No sanitization or validation logic is defined for the content read from the project files.
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the
Bashtool, specifically for building and testing the project (npx ng build,npx ng test,npx ng serve). These operations are standard for development but rely on the security and integrity of the local environment and the project's own configuration files.
Audit Metadata