typescript-expert

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The diagnostic script scripts/ts_diagnostic.py executes system commands such as npx, node, grep, and wc using subprocess.run. This is used to gather version information, check configuration files, and count type errors or assertions within the local source code.\n- [REMOTE_CODE_EXECUTION]: The skill instructions and diagnostic script utilize npx to run various tools including tsc, ts-migrate, typesync, tsx, ts-node, and @typescript/analyze-trace. These tools are downloaded and executed from the NPM registry as needed for analysis and migration tasks.\n- [DYNAMIC_EXECUTION]: The script scripts/ts_diagnostic.py utilizes subprocess.run with shell=True to perform dynamic command execution. This allows the script to process shell-specific features like output redirection and pipes for gathering diagnostics.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external project configuration files such as package.json and tsconfig.json to customize its recommendations.\n
  • Ingestion points: Files package.json and tsconfig.json are read by scripts/ts_diagnostic.py and the agent.\n
  • Boundary markers: None identified in the processing logic to prevent instructions within those files from influencing the agent's behavior.\n
  • Capability inventory: The skill can execute shell commands via subprocess and npx based on the environment detected.\n
  • Sanitization: No specific sanitization of input from these configuration files is performed before using the data to generate diagnostic reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:33 AM