dx-audit
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data, including source code files,
package.jsonconfigurations, and CLI command outputs, which creates a surface for indirect prompt injection. - Ingestion points: The skill (SKILL.md) instructs the agent to read
git diff,package.jsonexports, bin fields, and command outputs from the repository being audited. - Boundary markers: The instructions focus on locking the public surface but do not specify explicit delimiters or "ignore instructions" wrappers for the ingested content.
- Capability inventory: The agent is authorized to read files, execute local build entry points (e.g.,
node ./dist/cli.js), and run packaging tools likenpx publint. - Sanitization: The skill includes a mandatory safety instruction to "Inspect those scripts first or use a disposable checkout before calling --pack" to prevent the execution of potentially malicious lifecycle scripts (e.g.,
prepack). - [COMMAND_EXECUTION]: The skill performs local command execution of the software under audit (such as
node ./dist/cli.js --help) to verify DX behavior and usesnpxto run external diagnostic tools. - [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto fetch and execute thepublintand@arethetypeswrong/clipackages from the npm registry for package validation.
Audit Metadata