validate
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources, creating a potential vector for indirect instructions.
- Ingestion points: The agent is instructed to read test counts, log files (e.g.,
/tmp/test-output.log), and browser measurement outputs inSKILL.md. - Boundary markers: The instructions do not define delimiters or specific safety warnings to ignore instructions embedded within these external outputs.
- Capability inventory: The skill utilizes shell execution for
pnpm,git, andpnpxcommands, as well as file writing viatee. - Sanitization: There is no mention of sanitizing or validating the content of test logs or browser outputs before the agent processes them.
- [EXTERNAL_DOWNLOADS]: Fetches and runs utilities from standard package registries.
- Evidence: The instruction
pnpx node-actionlint <file>downloads the actionlint package from the official npm registry at runtime. - [COMMAND_EXECUTION]: Executes local shell commands and build scripts to verify code integrity.
- Evidence: Uses
pnpmfor linting and testing,git difffor change verification, andteefor capturing command output to files.
Audit Metadata