conformetry-validate

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project files to identify and fix conformance differences, which constitutes an indirect prompt injection surface. 1. Ingestion points: Local source files including TypeScript, Python, JSON, and Markdown, as well as output from the conformetry-validate command. 2. Boundary markers: Absent; the skill does not specify delimiters to separate external content from the agent's instructions. 3. Capability inventory: Execution of nx and conformetry CLI tools and file system write access to apply reported fixes. 4. Sanitization: Absent; there is no mention of content filtering or validation before processing.
  • [COMMAND_EXECUTION]: The skill requires the execution of shell commands such as nx run and conformetry validate. It also explicitly advises the agent to install python3 using system tools if it is reported as missing.
  • [EXTERNAL_DOWNLOADS]: The skill includes links to documentation and code examples hosted on GitHub in the JimmyPaolini/codebase repository, which is a developer-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 12:13 PM
Security Audit — agent-trust-hub — conformetry-validate