typescript-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/ts_diagnostic.pyusessubprocess.run(cmd, shell=True)for version checks and project audits. This is a functional requirement for the skill's diagnostic capabilities but is a notable execution pattern.\n- [DYNAMIC_EXECUTION]:SKILL.mdcontains a one-line JavaScript command executed vianode -eto extract project dependencies frompackage.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the analysis of project files.\n - Ingestion points: Diagnostics read
package.json,tsconfig.json, andsrc/directory files.\n - Boundary markers: None identified in the instructional flow or diagnostic scripts.\n
- Capability inventory: Shell command execution and file system access for builds and diagnostics.\n
- Sanitization: Project data is processed without specific filtering for malicious instructions.\n- [EXTERNAL_DOWNLOADS]: The skill uses
npxto run common development tools liketscandvitestfrom the npm registry, which is a well-known service.
Audit Metadata