lint-and-validate

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/lint_runner.py script executes ecosystem-standard linting tools to validate code quality.
  • Supported tools include npm, npx, ruff, mypy, and bandit.
  • Commands are executed using subprocess.run with argument lists, which is a secure pattern to prevent shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project files which may contain untrusted content to generate metrics.
  • Ingestion points: scripts/type_coverage.py reads content from .ts, .tsx, and .py files using glob patterns within the target directory.
  • Boundary markers: Analysis results are printed directly to the console without explicit delimiters or instructions to ignore embedded content.
  • Capability inventory: The skill utilizes subprocess.run for tool execution and Path.read_text for file access.
  • Sanitization: File content is processed via regular expressions to calculate statistics (e.g., usage of 'any' types) and is not executed or directly interpreted as agent instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — lint-and-validate