lint-and-validate
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/lint_runner.pyscript executes ecosystem-standard linting tools to validate code quality. - Supported tools include
npm,npx,ruff,mypy, andbandit. - Commands are executed using
subprocess.runwith argument lists, which is a secure pattern to prevent shell injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes project files which may contain untrusted content to generate metrics.
- Ingestion points:
scripts/type_coverage.pyreads content from.ts,.tsx, and.pyfiles using glob patterns within the target directory. - Boundary markers: Analysis results are printed directly to the console without explicit delimiters or instructions to ignore embedded content.
- Capability inventory: The skill utilizes
subprocess.runfor tool execution andPath.read_textfor file access. - Sanitization: File content is processed via regular expressions to calculate statistics (e.g., usage of 'any' types) and is not executed or directly interpreted as agent instructions.
Audit Metadata