angular-developer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill guides the agent to use standard Angular CLI commands for project lifecycle management, including ng new for project creation, ng build for validation, and ng generate for scaffolding. These commands are typical for developer-focused AI agents.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing dependencies from the NPM registry, such as @angular/material, tailwindcss, and @angular/aria. These resources originate from well-known services and trusted organizations.\n- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing project source code (e.g., components, configuration files), creating an attack surface for instructions embedded in data. However, the associated risk is low as the capabilities are limited to standard developer tooling.\n
  • Ingestion points: Reads project files including package.json, angular.json, and source code files as described in the documentation references.\n
  • Boundary markers: None identified.\n
  • Capability inventory: Execution of build, test, and project management commands via ng, npm, pnpm, and npx.\n
  • Sanitization: No content sanitization or isolation protocols are specified for the processed code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — angular-developer