tsdown
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill documents a legitimate open-source development tool (tsdown) created by the author (oakoss). No evidence of prompt injection, data exfiltration, or persistence mechanisms was found.
- [INDIRECT_PROMPT_INJECTION]: The skill operates on local project files, which constitutes a potential ingestion point for instructions if those files are maliciously crafted.
- Ingestion points: Metadata and configuration data ingested from
package.json,tsconfig.json, andtsdown.config.ts(SKILL.md, configuration.md). - Boundary markers: Standard structured data formats (JSON/TS) serve as delimiters.
- Capability inventory: File system writing to
dist, execution of build hooks, and potential network access via the plugin system. - Sanitization: Data is validated against internal schemas during the build process.
- [DYNAMIC_EXECUTION]: The tool supports programmatic features that execute logic during the build lifecycle.
- Logic execution: The
onSuccesshook (advanced-features.md) allows for custom asynchronous functions to run after builds. - Configuration loading: The skill uses TypeScript-based configuration files which are dynamically loaded and executed to resolve build settings.
Audit Metadata