typescript

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided code files (.ts, .js, package.json). This creates a surface where malicious instructions embedded in a project's source code or configuration could potentially influence the agent's behavior. However, the skill mitigates this by recommending strict data validation patterns using Zod at boundary points and providing a verification checklist that includes zero-error compilation requirements.
  • [SAFE]: The code examples provided for environment variable validation (DATABASE_URL, API_KEY) and subprocess management (Bun.spawn) represent standard, secure development practices for identifying and managing configuration and build processes in a TypeScript environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — typescript