jscodeshift

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and official repositories from trusted organizations, such as Facebook/Meta's jscodeshift repository and Martin Fowler's technical articles.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface as it is designed to ingest and transform external source code.
  • Ingestion points: Source code files are processed by the transformer function defined in individual codemod scripts.
  • Boundary markers: The guidelines do not specify delimiters or instructions to ignore embedded content within the source code being analyzed.
  • Capability inventory: The skill uses the jscodeshift API to perform AST transformations and generate updated source code via the toSource() method.
  • Sanitization: No specific sanitization techniques for untrusted code comments or identifiers are required by the provided rules.
  • [DYNAMIC_EXECUTION]: The rules describe standard runtime parsing of code strings using templates and the registration of custom collection methods, which are documented features of the jscodeshift framework used for automated refactoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:49 AM
Security Audit — agent-trust-hub — jscodeshift