skills/midudev/autoskills/oxlint/Gen Agent Trust Hub

oxlint

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development commands such as npx oxlint, npm run lint, and npx oxlint --init. These commands are used for running the linter, applying fixes, and initializing configuration files within the project environment.
  • [EXTERNAL_DOWNLOADS]: The skill references the download and execution of the oxlint and @oxlint/migrate packages from the npm registry using npx. It also suggests the installation of the eslint-plugin-oxlint package for projects migrating from ESLint.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing project source files and configuration metadata, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: The skill reads project source code files (including .js, .ts, .vue, .svelte, and .astro extensions) and configuration files like package.json and .oxlintrc.json.
  • Boundary markers: There are no specific instructions to use delimiters or boundary markers when the agent processes or presents the linter's output.
  • Capability inventory: The skill possesses the capability to execute shell commands via npx/npm and can modify or create files on the local filesystem (e.g., using --fix or --init).
  • Sanitization: No explicit sanitization or validation of the file content is performed by the skill prior to analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — oxlint