typescript-expert
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill employs standard shell commands such as
npx tsc,npm run, andnode -vto perform project analysis, type checking, and validation. - [COMMAND_EXECUTION]: The diagnostic script (
scripts/ts_diagnostic.py) utilizessubprocess.runwithshell=Trueto execute system utilities likegrepandwcfor codebase inspection. - [EXTERNAL_DOWNLOADS]: The skill leverages
npxto run various development tools (e.g.,ts-migrate,vitest,tsx), which may fetch and execute packages from the official npm registry. - [SAFE]: The skill possesses a surface for indirect prompt injection by processing project files like
package.jsonandtsconfig.jsonto detect the tooling ecosystem. - Ingestion points: Reads
package.json,tsconfig.json, and monorepo config files (e.g.,turbo.json,nx.json). - Boundary markers: No explicit markers or warnings are used when reading these project files.
- Capability inventory: Includes shell command execution in
SKILL.mdand subprocess calls inscripts/ts_diagnostic.py. - Sanitization: None detected; the skill relies on the structure of standard configuration files.
Audit Metadata