typescript-expert
Warn
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently uses shell commands to interact with the user's environment, including commands like
node -eto parse project data andnpm runto execute project-defined scripts. - [COMMAND_EXECUTION]: The diagnostic script
scripts/ts_diagnostic.pyutilizessubprocess.run(shell=True)to execute system commands, which is a sensitive pattern for potential command injection if project data is malicious. - [REMOTE_CODE_EXECUTION]: The instructions direct the agent to use
npxto execute various utilities such asts-migrate,typesync,vitest, andtsx. This involves downloading and executing packages from the npm registry at runtime. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted project files and executes commands based on their content.
- Ingestion points: Project configuration files (
package.json,tsconfig.json) and source code in thesrc/directory. - Boundary markers: None present; the agent treats project data as trusted instructions for build and test steps.
- Capability inventory: Shell execution (
npm run,npx), file reading, and subprocess management inscripts/ts_diagnostic.py. - Sanitization: There is no evidence of sanitization or validation of the scripts defined in
package.jsonbefore they are executed vianpm run.
Audit Metadata