typescript
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided code files (.ts, .js, package.json). This creates a surface where malicious instructions embedded in a project's source code or configuration could potentially influence the agent's behavior. However, the skill mitigates this by recommending strict data validation patterns using Zod at boundary points and providing a verification checklist that includes zero-error compilation requirements.
- [SAFE]: The code examples provided for environment variable validation (DATABASE_URL, API_KEY) and subprocess management (Bun.spawn) represent standard, secure development practices for identifying and managing configuration and build processes in a TypeScript environment.
Audit Metadata