tsdown
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of the
--on-successCLI flag and build hooks (e.g.,build:done), which allow the execution of arbitrary shell commands or JavaScript code after a build process completes. - Evidence in
references/config.md:--on-success "echo Done!" - Evidence in
references/features.md:tsdown --watch --on-success "node dist/index.mjs" - Evidence in
references/advanced.md:hooks: { 'build:done': async (context) => { ... } } - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and execute packages using
npxand to install various development dependencies from the npm registry. These resources include vendor-specific tools and well-known library plugins. - Evidence in
SKILL.md:npm i -D tsdown typescript - Evidence in
references/advanced.md:npx tsdown-migrate - Evidence in
references/features.md:npx create-tsdown@latest,pnpm add -D unplugin-lightningcss,@rollup/plugin-babel,babel-plugin-react-compiler, etc. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process project configuration files (
tsdown.config.ts,package.json) and project source code. These files are untrusted external inputs that could contain malicious instructions if the project being built is compromised. - Ingestion points:
tsdown.config.ts,package.json, and source files specified in theentryfield. - Boundary markers: None mentioned for the agent to distinguish between its instructions and the content of the config files.
- Capability inventory: The skill can execute shell commands via
on-successandhooks, perform file system writes for the build output, and run arbitrary JavaScript through the plugin system. - Sanitization: None mentioned for the interpolation of configuration values or file content.
Audit Metadata