best-practice-ts

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown documentation and code examples illustrating TypeScript best practices. No executable scripts or malicious instructions were found.
  • [PROMPT_INJECTION]: The skill's instructions are focused on coding standards and do not contain any attempts to override agent safety protocols or hijack behavior.
  • [DATA_EXFILTRATION]: No evidence of data exfiltration was found. Code examples use local or placeholder paths and URLs.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote code. It mentions standard development tools like Vitest and Zod as recommended project dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill specifically addresses the risk of untrusted data (including LLM tool-call arguments) in Chapter 24. It provides a defensive evidence chain by identifying ingestion points (process.env, JSON.parse, fetch), recommending Zod as a boundary marker, and providing sanitization patterns through schema validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 11:28 PM
Security Audit — agent-trust-hub — best-practice-ts