typescript-expert

Warn

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently uses shell commands to interact with the user's environment, including commands like node -e to parse project data and npm run to execute project-defined scripts.
  • [COMMAND_EXECUTION]: The diagnostic script scripts/ts_diagnostic.py utilizes subprocess.run(shell=True) to execute system commands, which is a sensitive pattern for potential command injection if project data is malicious.
  • [REMOTE_CODE_EXECUTION]: The instructions direct the agent to use npx to execute various utilities such as ts-migrate, typesync, vitest, and tsx. This involves downloading and executing packages from the npm registry at runtime.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted project files and executes commands based on their content.
  • Ingestion points: Project configuration files (package.json, tsconfig.json) and source code in the src/ directory.
  • Boundary markers: None present; the agent treats project data as trusted instructions for build and test steps.
  • Capability inventory: Shell execution (npm run, npx), file reading, and subprocess management in scripts/ts_diagnostic.py.
  • Sanitization: There is no evidence of sanitization or validation of the scripts defined in package.json before they are executed via npm run.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — typescript-expert