angular-developer

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the Angular CLI (ng) and npx for common development tasks, including project creation (ng new), building (ng build), testing (ng test), and starting the Model Context Protocol server (npx @angular/cli mcp). These commands are standard and appropriate for the skill's purpose.
  • [EXTERNAL_DOWNLOADS]: The instructions cover adding dependencies and configuring environments using npm install, npx, and ng add. These actions target well-known and reputable packages such as @angular/core, @angular/material, and tailwindcss.
  • [INDIRECT_PROMPT_INJECTION]: As a development assistant that analyzes project files to generate code and guidance, the skill possesses an inherent indirect prompt injection surface.
  • Ingestion points: The agent is instructed to read and analyze local project files including package.json, TypeScript logic, and HTML templates to provide version-specific advice.
  • Boundary markers: The skill does not provide specific instructions to use delimiters or ignore potential commands embedded within the code files it analyzes.
  • Capability inventory: The agent has the capability to write files, execute build/test commands, and install packages.
  • Sanitization: No explicit sanitization logic or validation steps for content extracted from user project files are mentioned in the behavior guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — angular-developer