typescript-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/ts_diagnostic.py uses subprocess.run(cmd, shell=True) for version checks and project audits. This is a functional requirement for the skill's diagnostic capabilities but is a notable execution pattern.\n- [DYNAMIC_EXECUTION]: SKILL.md contains a one-line JavaScript command executed via node -e to extract project dependencies from package.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the analysis of project files.\n
  • Ingestion points: Diagnostics read package.json, tsconfig.json, and src/ directory files.\n
  • Boundary markers: None identified in the instructional flow or diagnostic scripts.\n
  • Capability inventory: Shell command execution and file system access for builds and diagnostics.\n
  • Sanitization: Project data is processed without specific filtering for malicious instructions.\n- [EXTERNAL_DOWNLOADS]: The skill uses npx to run common development tools like tsc and vitest from the npm registry, which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — typescript-expert