skills/oakoss/agent-skills/tsdown/Gen Agent Trust Hub

tsdown

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [SAFE]: The skill documents a legitimate open-source development tool (tsdown) created by the author (oakoss). No evidence of prompt injection, data exfiltration, or persistence mechanisms was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on local project files, which constitutes a potential ingestion point for instructions if those files are maliciously crafted.
  • Ingestion points: Metadata and configuration data ingested from package.json, tsconfig.json, and tsdown.config.ts (SKILL.md, configuration.md).
  • Boundary markers: Standard structured data formats (JSON/TS) serve as delimiters.
  • Capability inventory: File system writing to dist, execution of build hooks, and potential network access via the plugin system.
  • Sanitization: Data is validated against internal schemas during the build process.
  • [DYNAMIC_EXECUTION]: The tool supports programmatic features that execute logic during the build lifecycle.
  • Logic execution: The onSuccess hook (advanced-features.md) allows for custom asynchronous functions to run after builds.
  • Configuration loading: The skill uses TypeScript-based configuration files which are dynamically loaded and executed to resolve build settings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — tsdown