pnpm-workspace

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents extensive use of the pnpm CLI, including filtering flags (--filter), recursive execution (-r), and package management commands. These are standard operations for a workspace management tool.
  • [EXTERNAL_DOWNLOADS]: The documentation references pnpm install, pnpm dlx, and GitHub Actions for CI/CD pipelines. These patterns involve downloading and executing code from established registries (npm) and trusted GitHub Actions (actions/checkout, pnpm/action-setup, changesets/action), which align with standard development practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes command patterns such as --filter "[origin/main]" or --filter <name>. If an agent using this skill interpolates untrusted data (like branch names or package names from an external PR) directly into these flags without sanitization, it could lead to command injection. This is a common surface for indirect prompt injection, but the documentation itself provides the patterns for legitimate use.
  • [CREDENTIALS_UNSAFE]: The CI/CD examples correctly demonstrate the use of GitHub Secrets (${{ secrets.NPM_TOKEN }}) for handling sensitive credentials, which is a security best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — pnpm-workspace