typescript

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical guide for TypeScript development. All instructions focus on improving type safety, compiler configuration, and developer productivity.
  • [REMOTE_CODE_EXECUTION]: The skill mentions the native Go port of the TypeScript compiler (@typescript/native-preview / tsgo) and suggests running it via npx. This is documented neutrally as it refers to a well-known preview tool from the TypeScript ecosystem for performance optimization.
  • [COMMAND_EXECUTION]: The scripts/verify.sh file executes standard TypeScript type-checking commands (tsc or tsgo) against temporary files created in a sandbox environment (mktemp -d). These commands are used solely for local verification of the type system's exhaustiveness and strictness enforcement.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user prompts related to TypeScript code and configuration. It includes clear boundary markers in its evaluation logic (evals/cases.yaml) to distinguish between language-level questions and runtime or framework-specific tasks, which serves as a safety best practice for routing and context management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — typescript