pnpm
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted project configuration files while having command execution capabilities. Ingestion points: pnpm-workspace.yaml and package.json (SKILL.md). Boundary markers: Absent. Capability inventory: pnpm install and pnpm run commands (SKILL.md, references/pnpm-2026-02-18.md). Sanitization: Absent. The skill mitigates this risk by recommending security practices such as frozen lockfiles and dependency audits.
Audit Metadata