nodejs-development
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The README.md file contains a command to download and execute the Node Version Manager (nvm) installation script using a pipe to bash (
curl | bash). The script is sourced from the official nvm-sh repository on GitHub. - [EXTERNAL_DOWNLOADS]: Fetches the installation script for nvm from
raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh. - [COMMAND_EXECUTION]: The SKILL.md and EXAMPLES.md files document the use of the
child_processmodule, includingexec,spawn, andforkmethods, which allow the execution of system commands. - [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for ingesting untrusted data through HTTP request bodies and command-line arguments, which are then used in database queries, file operations, and shell commands.
- Ingestion points: HTTP request bodies (
req.body), request streams (req.on('data')), and CLI arguments (process.argv) inSKILL.mdandEXAMPLES.md. - Boundary markers: The skill includes recommendations for using
express-validator,helmet, and parameterized queries to delimit and validate data. - Capability inventory: Includes full file system access (
fs), network operations (https,fetch), and subprocess execution (child_process). - Sanitization: Provides examples of input sanitization functions, schema validation with Mongoose, and password hashing with
bcrypt.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh - DO NOT USE without thorough review
Audit Metadata