skills/janpereira-dev/ngautopilot/Angular v22 Host Directive Conflicting Alias Gate/Gen Agent Trust Hub
Angular v22 Host Directive Conflicting Alias Gate
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (project source code,
package.json, and lockfiles) and has the capability to execute build or test scripts found within the repository. While this is standard for development tools, it creates a potential surface where malicious code in a repository could attempt to influence the agent's behavior. - Ingestion points: Reads
package.json, lockfiles,angular.json,tsconfig, and component source code from the target repository. - Boundary markers: None specified to distinguish between skill instructions and data content.
- Capability inventory: Executes existing build, test, and lint scripts defined in the target repository's configuration.
- Sanitization: No explicit sanitization or validation of the repository's scripts or file content is mentioned before execution.
Audit Metadata