megalinter-fix
Fail
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
npx mega-linter-runnerto apply automated fixes to the codebase. This operation uses the official tool provided by the skill's author and follows standard developer workflows. Manual fixes are also guided by instructions in the repository. - [EXTERNAL_DOWNLOADS]: Uses
npxto download the MegaLinter runner from the npm registry. It also fetches documentation and rule definitions from various project repositories to assist the agent in performing manual fixes. These downloads originate from well-known technology domains and the official maintainers. - [INDIRECT_PROMPT_INJECTION]: The skill processes linter error output, which is a potential surface for indirect injection. However, the skill mitigates this risk by providing specific, vetted fix guides for each linter and requiring user confirmation for any ambiguous or behavior-changing modifications.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata