typescript-pro

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes and modifies TypeScript code from the user's workspace.\n
  • Ingestion points: Reads and processes source files from the current workspace to identify type contracts and perform refactors.\n
  • Boundary markers: Absent; the instructions do not provide delimiters to distinguish code from agent instructions.\n
  • Capability inventory: The skill uses workspace-write permissions to modify code files in the project.\n
  • Sanitization: No sanitization or validation of the file content is mentioned in the instructions.\n- [SAFE]: The primary instructions are focused on architectural integrity and type safety. No signs of malicious intent or data exfiltration were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 01:40 AM
Security Audit — agent-trust-hub — typescript-pro