skills/grupous/gpus/typescript-expert/Gen Agent Trust Hub

typescript-expert

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs standard shell commands such as npx tsc, npm run, and node -v to perform project analysis, type checking, and validation.
  • [COMMAND_EXECUTION]: The diagnostic script (scripts/ts_diagnostic.py) utilizes subprocess.run with shell=True to execute system utilities like grep and wc for codebase inspection.
  • [EXTERNAL_DOWNLOADS]: The skill leverages npx to run various development tools (e.g., ts-migrate, vitest, tsx), which may fetch and execute packages from the official npm registry.
  • [SAFE]: The skill possesses a surface for indirect prompt injection by processing project files like package.json and tsconfig.json to detect the tooling ecosystem.
  • Ingestion points: Reads package.json, tsconfig.json, and monorepo config files (e.g., turbo.json, nx.json).
  • Boundary markers: No explicit markers or warnings are used when reading these project files.
  • Capability inventory: Includes shell command execution in SKILL.md and subprocess calls in scripts/ts_diagnostic.py.
  • Sanitization: None detected; the skill relies on the structure of standard configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — typescript-expert