megalinter-fix

Fail

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes npx mega-linter-runner to apply automated fixes to the codebase. This operation uses the official tool provided by the skill's author and follows standard developer workflows. Manual fixes are also guided by instructions in the repository.
  • [EXTERNAL_DOWNLOADS]: Uses npx to download the MegaLinter runner from the npm registry. It also fetches documentation and rule definitions from various project repositories to assist the agent in performing manual fixes. These downloads originate from well-known technology domains and the official maintainers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes linter error output, which is a potential surface for indirect injection. However, the skill mitigates this risk by providing specific, vetted fix guides for each linter and requiring user confirmation for any ambiguous or behavior-changing modifications.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 7, 2026, 10:41 PM
Security Audit — agent-trust-hub — megalinter-fix