skills/fubits1/svelte-skills/validate/Gen Agent Trust Hub

validate

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources, creating a potential vector for indirect instructions.
  • Ingestion points: The agent is instructed to read test counts, log files (e.g., /tmp/test-output.log), and browser measurement outputs in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific safety warnings to ignore instructions embedded within these external outputs.
  • Capability inventory: The skill utilizes shell execution for pnpm, git, and pnpx commands, as well as file writing via tee.
  • Sanitization: There is no mention of sanitizing or validating the content of test logs or browser outputs before the agent processes them.
  • [EXTERNAL_DOWNLOADS]: Fetches and runs utilities from standard package registries.
  • Evidence: The instruction pnpx node-actionlint <file> downloads the actionlint package from the official npm registry at runtime.
  • [COMMAND_EXECUTION]: Executes local shell commands and build scripts to verify code integrity.
  • Evidence: Uses pnpm for linting and testing, git diff for change verification, and tee for capturing command output to files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:07 AM
Security Audit — agent-trust-hub — validate