oxlint
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development commands such as
npx oxlint,npm run lint, andnpx oxlint --init. These commands are used for running the linter, applying fixes, and initializing configuration files within the project environment. - [EXTERNAL_DOWNLOADS]: The skill references the download and execution of the
oxlintand@oxlint/migratepackages from the npm registry usingnpx. It also suggests the installation of theeslint-plugin-oxlintpackage for projects migrating from ESLint. - [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing project source files and configuration metadata, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: The skill reads project source code files (including
.js,.ts,.vue,.svelte, and.astroextensions) and configuration files likepackage.jsonand.oxlintrc.json. - Boundary markers: There are no specific instructions to use delimiters or boundary markers when the agent processes or presents the linter's output.
- Capability inventory: The skill possesses the capability to execute shell commands via
npx/npmand can modify or create files on the local filesystem (e.g., using--fixor--init). - Sanitization: No explicit sanitization or validation of the file content is performed by the skill prior to analysis.
Audit Metadata