javascript-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process and analyze content from project files such as package.json, README.md, and source code. This creates a surface where malicious instructions embedded in these files could potentially influence agent behavior.
  • Ingestion points: The operating procedure in SKILL.md requires the agent to 'Inspect the repository' and 'Read package.json, the relevant source files'.
  • Boundary markers: The skill includes a dedicated 'Security at runtime boundaries' section, explicitly directing the agent to treat external responses and request parameters as untrusted.
  • Capability inventory: The agent has the ability to implement code changes, run test scripts, and perform code reviews.
  • Sanitization: The skill explicitly mandates the use of parameterized APIs, safe sinks, and output encoding to handle external data correctly.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:49 AM
Security Audit — agent-trust-hub — javascript-engineering