skills/howells/skills/typecase/Gen Agent Trust Hub

typecase

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses scripts/census-typography.py to ingest and process source code from the local repository. If the scanned files contain malicious instructions disguised as typography utilities, they could influence the agent's behavior during the audit and migration process.\n
  • Ingestion points: The script reads source files with various web-related extensions including .tsx, .jsx, .ts, .js, .vue, .svelte, .astro, .html, and .css.\n
  • Boundary markers: Data is passed to the agent as a summarized census report.\n
  • Capability inventory: The agent is instructed to rewrite CSS files, write migration mappings, and configure linting rules.\n
  • Sanitization: The script uses targeted regular expressions to extract specific typography tokens, providing a layer of filtering before the data reaches the agent.\n- [EXTERNAL_DOWNLOADS]: The skill instructions reference the @howells/lint Node.js package for enforcing typography roles. This is a vendor-owned resource used for development linting and is a standard dependency for the described workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:29 PM
Security Audit — agent-trust-hub — typecase