fix-any-types

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run standard command-line tools including npx tsc, grep, and git. These commands are used for baseline type checking, searching for existing definitions, and verifying the impact of changes, which aligns with the skill's intended purpose.
  • [EXTERNAL_DOWNLOADS]: The use of npx tsc may involve fetching the TypeScript compiler from the official npm registry if the package is not already present in the local environment. This is a standard development operation using a well-known tool from a trusted ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided TypeScript source files to infer type information (Step 2 and Step 3). While this involves ingesting untrusted data, the risk is mitigated by a verification step where the agent runs the TypeScript compiler (npx tsc) to ensure the changes are syntactically and logically sound.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — fix-any-types