dev-requirements
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using 'npx ai-devkit@latest' to perform operations such as linting documentation, searching memory, and initializing feature doc paths. These are standard operations for the tool's intended purpose.
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes the 'ai-devkit' package from the npm registry using npx. As this package is the vendor's primary tool and registry.npmjs.org is a well-known service, this is documented as expected behavior.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from project files (e.g., README.md, docs/ai) and memory search results. Ingestion points: README.md, .ai-devkit.json, docs/ai directory, and memory search results. Boundary markers: Absent; there are no specific instructions to ignore embedded commands within the processed documentation. Capability inventory: Execution of npx commands and local file writing. Sanitization: None identified; the skill relies on the agent to interpret documentation content for planning.
Audit Metadata