solidjs-v2-migration
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and modify an existing Solid 1.x codebase, creating a surface for potential indirect prompt injection from comments or code strings. 1. Ingestion points: Agent reads user source code (SKILL.md Step 0). 2. Boundary markers: Absent. 3. Capability inventory: File-system writes and potential command execution (Pass 1 and 3). 4. Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install or update official packages like solid-js, @solidjs/web, and @solidjs/vite-plugin. These are official resources from the well-known SolidJS framework ecosystem.
- [COMMAND_EXECUTION]: The workflow involves running development and test commands (e.g., run dev) to verify migration diagnostics and test suite results as described in Pass 3.
Audit Metadata