typescript-expert
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The diagnostic script
scripts/ts_diagnostic.pyexecutes system commands such asnpx,node,grep, andwcusingsubprocess.run. This is used to gather version information, check configuration files, and count type errors or assertions within the local source code.\n- [REMOTE_CODE_EXECUTION]: The skill instructions and diagnostic script utilizenpxto run various tools includingtsc,ts-migrate,typesync,tsx,ts-node, and@typescript/analyze-trace. These tools are downloaded and executed from the NPM registry as needed for analysis and migration tasks.\n- [DYNAMIC_EXECUTION]: The scriptscripts/ts_diagnostic.pyutilizessubprocess.runwithshell=Trueto perform dynamic command execution. This allows the script to process shell-specific features like output redirection and pipes for gathering diagnostics.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external project configuration files such aspackage.jsonandtsconfig.jsonto customize its recommendations.\n - Ingestion points: Files
package.jsonandtsconfig.jsonare read byscripts/ts_diagnostic.pyand the agent.\n - Boundary markers: None identified in the processing logic to prevent instructions within those files from influencing the agent's behavior.\n
- Capability inventory: The skill can execute shell commands via
subprocessandnpxbased on the environment detected.\n - Sanitization: No specific sanitization of input from these configuration files is performed before using the data to generate diagnostic reports.
Audit Metadata