typescript-pro
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes and modifies TypeScript code from the user's workspace.\n
- Ingestion points: Reads and processes source files from the current workspace to identify type contracts and perform refactors.\n
- Boundary markers: Absent; the instructions do not provide delimiters to distinguish code from agent instructions.\n
- Capability inventory: The skill uses
workspace-writepermissions to modify code files in the project.\n - Sanitization: No sanitization or validation of the file content is mentioned in the instructions.\n- [SAFE]: The primary instructions are focused on architectural integrity and type safety. No signs of malicious intent or data exfiltration were found.
Audit Metadata