nestjs-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted project data, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill reads
package.json,nest-cli.json,tsconfig.json, and various*.module.tsfiles within thesrcdirectory to identify the project structure and dependencies. - Boundary markers: There are no explicit instructions or delimiters used when processing file content to distinguish between data and potential instructions.
- Capability inventory: The skill utilizes shell capabilities including
grep,sed,find,xargs, and executes project scripts vianpm run build/test/lint. - Sanitization: No sanitization or validation of the ingested file content is performed before processing.- [COMMAND_EXECUTION]: The skill uses standard diagnostic shell commands to analyze the environment.
- Evidence: Commands like
test -f,grep,sed,find, andnest infoare used to detect project configuration and versioning.
Audit Metadata