javascript-pro

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed code patterns for the Node.js child_process module, specifically exec and spawn, enabling the execution of shell commands and external scripts. These are presented as educational examples for senior developer workflows.
  • [EXTERNAL_DOWNLOADS]: Documents the use of the Fetch API and Service Workers for network communication and resource caching. It also demonstrates utilizing the esm.sh CDN to load the React library via browser import maps.
  • [REMOTE_CODE_EXECUTION]: Includes guidance on implementing Web Workers and Worker Threads to execute JavaScript tasks in isolated background threads for performance optimization.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core workflow.
  • Ingestion points: The agent is instructed in SKILL.md to analyze user requirements and review project files like package.json before implementation.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the analyzed data.
  • Capability inventory: The skill facilitates extensive capabilities including file system writes (writeFile), network access (fetch), and process execution (exec) as shown in references/node-essentials.md and references/browser-apis.md.
  • Sanitization: While references/modern-syntax.md contains an example of string sanitization using regex, there is no mandate to sanitize incoming project data before it influences code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 07:23 AM