nodejs-development

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The README.md file contains a command to download and execute the Node Version Manager (nvm) installation script using a pipe to bash (curl | bash). The script is sourced from the official nvm-sh repository on GitHub.
  • [EXTERNAL_DOWNLOADS]: Fetches the installation script for nvm from raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh.
  • [COMMAND_EXECUTION]: The SKILL.md and EXAMPLES.md files document the use of the child_process module, including exec, spawn, and fork methods, which allow the execution of system commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for ingesting untrusted data through HTTP request bodies and command-line arguments, which are then used in database queries, file operations, and shell commands.
  • Ingestion points: HTTP request bodies (req.body), request streams (req.on('data')), and CLI arguments (process.argv) in SKILL.md and EXAMPLES.md.
  • Boundary markers: The skill includes recommendations for using express-validator, helmet, and parameterized queries to delimit and validate data.
  • Capability inventory: Includes full file system access (fs), network operations (https, fetch), and subprocess execution (child_process).
  • Sanitization: Provides examples of input sanitization functions, schema validation with Mongoose, and password hashing with bcrypt.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:23 AM
Security Audit — agent-trust-hub — nodejs-development