effect-ts
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSOBFUSCATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides documentation on using
@effect/platformfor powerful system interactions like file system access (FileSystem) and command execution (Command). These features represent a potential vulnerability surface if an agent using this skill processes untrusted external data without proper validation. - Ingestion points: Data ingestion via
fetch(documented inreferences/core-concepts.mdandreferences/sched-scheduling.md) andFileSystem.readFileString(documented inreferences/plat-platform.md). - Capability inventory: Instructions for
Command.maketo execute shell processes andFileSystem.writeFilefor file modification (documented inreferences/plat-platform.md). - Sanitization: The documentation consistently promotes the use of
effect/Schemafor strict data validation and provides detailed guidance on sanitizing inputs (found inreferences/schema-basics.mdandreferences/schema-advanced.md). - [EXTERNAL_DOWNLOADS]: The documentation includes instructions for installing official
@effect/*and@opentelemetry/*packages from public registries. - Evidence: Installation commands like
npm install effect @effect/schema @effect/platformare provided throughout the getting started guides. These target well-known, established libraries in the TypeScript ecosystem. - [OBFUSCATION]: The skill uses Base64 and Hex encoding within code examples for educational purposes to demonstrate the library's ability to decode such formats.
- Evidence:
references/schema-advanced.mdcontains examples usingSchema.StringFromBase64with the inputZm9vYmFy(decodes to "foobar") andSchema.StringFromHexwith a hex sequence. These are benign and intended for developer education.
Audit Metadata