javascript-typescript

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package does not contain executable code; it consists of instructional markdown and code templates designed to guide an AI agent in generating high-quality JavaScript and TypeScript code. No instances of obfuscation, credential exfiltration, or unauthorized command execution were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user requirements to generate functional application logic (e.g., Express APIs, React components), which is an inherent attack surface for indirect prompt injection. However, the skill provides robust security instructions and templates to mitigate this.
  • Ingestion points: User-provided software specifications, architecture descriptions, and endpoint requirements handled by the agent.
  • Boundary markers: The skill emphasizes the 'Expert' persona and mandates the application of 'Security best practices' and 'TypeScript Type Safety' as foundational constraints.
  • Capability inventory: The templates involve database operations via Prisma, network communication via Express and Fetch, and client-side storage management.
  • Sanitization: The provided templates include specific input validation patterns (e.g., validateCreateUserDto, isValidEmail), secure password hashing (hashPassword), and centralized error handling middleware to manage external data safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — javascript-typescript