vitest-migration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructions involve runtime modification of the Node.js module system to facilitate testing. Specifically, it recommends patching
Module._loadandModule._resolveFilenameintools/vitest/setup.mtsto handle CommonJS mocking and custom package resolution. It also utilizes the--requirenode flag viaexecArgvto preload a safety write-guard script during execution. - [EXTERNAL_DOWNLOADS]: The skill uses the
nx-cloudCLI tool to download sandbox reports from Nx Cloud (npx nx-cloud get sandbox-reports), which is a well-known service used for performance tracking in Nx-based projects. - [COMMAND_EXECUTION]: The skill performs extensive command-line operations using standard development tools including
nx,pnpm,git, and the GitHub CLI (gh). It also uses common system utilities such asgrep,sed,find, andperlfor repository analysis and automated code modifications (codemods). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources that could contain untrusted instructions.
- Ingestion points: Pull request metadata and code diffs retrieved via
gh pr viewandgh pr diff, as well as source file content from thepackages/directory. - Boundary markers: None identified in the instructions for separating untrusted PR content from agent instructions.
- Capability inventory: The skill has broad capabilities including file system write access, execution of various shell commands (Bash), and network access through sanctioned developer tools.
- Sanitization: No explicit sanitization or filtering of PR data or source code is implemented before the agent processes the content.
Audit Metadata