angular-developer
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the Angular CLI (
ng) andnpxfor common development tasks, including project creation (ng new), building (ng build), testing (ng test), and starting the Model Context Protocol server (npx @angular/cli mcp). These commands are standard and appropriate for the skill's purpose. - [EXTERNAL_DOWNLOADS]: The instructions cover adding dependencies and configuring environments using
npm install,npx, andng add. These actions target well-known and reputable packages such as@angular/core,@angular/material, andtailwindcss. - [INDIRECT_PROMPT_INJECTION]: As a development assistant that analyzes project files to generate code and guidance, the skill possesses an inherent indirect prompt injection surface.
- Ingestion points: The agent is instructed to read and analyze local project files including
package.json, TypeScript logic, and HTML templates to provide version-specific advice. - Boundary markers: The skill does not provide specific instructions to use delimiters or ignore potential commands embedded within the code files it analyzes.
- Capability inventory: The agent has the capability to write files, execute build/test commands, and install packages.
- Sanitization: No explicit sanitization logic or validation steps for content extracted from user project files are mentioned in the behavior guidelines.
Audit Metadata