lint-and-validate
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/lint_runner.pyutilizessubprocess.runto execute development commands such asnpm run lint,npx tsc,ruff check, andmypy. These commands are triggered based on the detection of standard project manifest files (e.g.,package.json,pyproject.toml) and are executed within the project directory. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the following factors:
- Ingestion points:
scripts/lint_runner.pyreads project manifests likepackage.json, whilescripts/type_coverage.pyreads all.ts,.tsx, and.pysource files within the target directory. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded malicious content within the analyzed files.
- Capability inventory: The skill has the ability to execute shell commands via
subprocess.runinscripts/lint_runner.py. - Sanitization: The skill performs no sanitization or validation of the content read from files before it is processed or used to determine linter execution. The risk is considered low as the actions are confined to standard local development tooling.
Audit Metadata