nodejs-expert

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The instructions in SKILL.md recommend adding an admin/test method to each controller as a smoke test. This guidance, if followed without explicit instructions to implement authentication and authorization guards, could lead to the creation of unprotected administrative endpoints in production environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reviewing and refactoring user-provided code, which creates a surface for indirect prompt injection attacks. Malicious instructions could be embedded within the code being analyzed (e.g., in comments or string literals).
  • Ingestion points: User-provided code snippets passed to the agent for review, as described in the SKILL.md examples.
  • Boundary markers: The instructions lack explicit boundary markers or warnings to ignore instructions embedded within the data being reviewed.
  • Capability inventory: The skill has access to Read, Write, Edit, Bash, Grep, and Glob tools, providing a significant impact surface if an injection is successful.
  • Sanitization: There is no evidence of sanitization or validation logic for the input code before it is processed by the model.
  • [COMMAND_EXECUTION]: The Memory Protocol section in SKILL.md directs the agent to execute a shell command (cat .claude/context/memory/learnings.md) to retrieve session state. While this is a common pattern for context management, it represents a hardcoded command execution pattern within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:54 PM
Security Audit — agent-trust-hub — nodejs-expert