skills/pepsi1978/proggs/pm2/Gen Agent Trust Hub

pm2

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Installs the PM2 process manager globally via 'npm install -g pm2'.
  • [COMMAND_EXECUTION]: Generates and suggests the execution of multiple command files and PowerShell scripts to control background processes.
  • [EXTERNAL_DOWNLOADS]: Downloads the PM2 package from the public npm registry.
  • [PROMPT_INJECTION]: Reads untrusted project data (e.g., 'package.json', 'vite.config.js', 'requirements.txt') to dynamically generate service names and port configurations. This creates an indirect prompt injection surface where malicious local files could influence the generated execution parameters.
  • Ingestion points: Project configuration files and manifests (e.g. 'package.json', 'vite.config.js', 'next.config.js', 'requirements.txt', 'go.mod') in SKILL.md.
  • Boundary markers: None present.
  • Capability inventory: Global software installation, file writing, and system command execution via PM2 across generated files.
  • Sanitization: No sanitization or escaping of project-derived metadata before interpolation into generated scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 06:27 PM
Security Audit — agent-trust-hub — pm2