effect-ts
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides structured documentation and architectural patterns for TypeScript development using the Effect library. All referenced tools and practices align with official library documentation.
- [SAFE]: The documentation includes explicit security guidance, such as using the Redacted module to wrap sensitive data like API keys, ensuring they are not accidentally exposed in logs or console output.
- [SAFE]: All identified Node.js dependencies are legitimate packages within the Effect ecosystem or standard testing and observability tools.
- [INDIRECT_PROMPT_INJECTION]: The skill allows the agent to ingest project code via Read, Grep, and Glob tools. 1. Ingestion points: Project files accessed via Read and Grep tools. 2. Boundary markers: None explicitly implemented in the skill instructions to separate project data from instructions. 3. Capability inventory: The agent is restricted to reading and analyzing code; it lacks permissions for Write, Shell, or network access. 4. Sanitization: Not present in the static documentation. The overall risk is negligible as the agent has no way to persist changes, execute commands, or exfiltrate data.
Audit Metadata