javascript-pro

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill mentions using eslint --fix and jest as part of the validation and testing workflow in SKILL.md. These are standard developer tools and their use is scoped to project maintenance and code quality.
  • [REMOTE_CODE_EXECUTION]: The references/node-essentials.md file contains documentation on using child_process (spawn, exec) and worker_threads. These are provided as educational references for Node.js development and are not used by the skill to execute arbitrary or untrusted code.
  • [DATA_EXPOSURE]: Documentation includes examples of using fs/promises for file operations and process.env for configuration. These are standard practices in Node.js development and no specific sensitive paths or exfiltration patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — javascript-pro