skills/honestjs/skills/honest/Gen Agent Trust Hub

honest

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of official framework packages from the vendor (@honestjs) and the Hono ecosystem via package managers like Bun.
  • [COMMAND_EXECUTION]: Provides instructions for using the honestjs CLI to scaffold new projects and generate application components such as controllers, services, and modules. This includes management of local templates and the use of flags like --force to overwrite existing files.
  • [DYNAMIC_EXECUTION]: The framework's tooling, specifically the honestjs generate command and the @honestjs/rpc-plugin, programmatically creates source code files and client libraries based on project metadata and templates.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface where tooling processes user-provided source code (e.g., controller definitions and DTOs) to generate API documentation and RPC clients.
  • Ingestion points: User-defined source code files, controller definitions, and local template repositories.
  • Boundary markers: Not explicitly defined in the documentation.
  • Capability inventory: File system writes for code generation and artifact production (SKILL.md, @honestjs/rpc-plugin).
  • Sanitization: The skill relies on the internal parsing logic of the Honest.js CLI and plugins to handle user-defined code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:40 AM
Security Audit — agent-trust-hub — honest