arkenv
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions include commands for project setup and validation, specifically
pnpm dlx arkenv initandarkenv check. These are standard CLI operations intended for initializing the library and verifying environment configurations. - [EXTERNAL_DOWNLOADS]: The skill references several Node.js packages including
@arkenv/core,@arkenv/standard,@arkenv/vite-plugin,@arkenv/bun-plugin,@arkenv/nextjs, and@arkenv/nuxt, along with external validation libraries likezodandvalibot. These are standard dependencies required for the library's functionality and framework integrations. - [INDIRECT_PROMPT_INJECTION]: The skill operates on project-specific data such as environment variable files and schema definitions (
env.ts). - Ingestion points: Reads environment variable values and TypeScript schema definitions from the local project.
- Boundary markers: The skill does not explicitly define prompt boundary markers or "ignore" instructions for the agent when processing these files.
- Capability inventory: Performs file system modifications (scaffolding
env.ts) and shell command execution via thearkenvCLI tool. - Sanitization: The primary purpose of the library is to provide validation and coercion for environment variables, which acts as a sanitization layer for the data it processes.
Audit Metadata