nuqs-codemod-runner
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates several system utilities and local project scripts to analyze and modify the codebase.\n
- Utilizes
ripgrep(rg) for high-performance pattern matching andjqfor manipulating JSON data inscripts/scan.shandscripts/apply.sh.\n - Uses
gitacross multiple scripts to validate the repository's clean state, parse the current HEAD, and perform file restorations in case of failure.\n - Employs
python3for date calculations to ensure scan data remains fresh before application.\n - Executes project-specific verification commands, such as
npm run lintandnpx tsc, usingevalwithinscripts/verify.sh.\n- [EXTERNAL_DOWNLOADS]: The skill uses well-known package runners to fetch standard tools from official registries.\n scripts/apply.shinvokesnpx --yes jscodeshift@latestto obtain the migration tool from the npm registry.\nscripts/verify.shinvokesnpx tsc(depending on configuration) to run type-checking.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface that processes untrusted local source code, which is then summarized in a report for the agent and user.\n- Ingestion points:
scripts/scan.shreads code from.ts,.tsx,.js, and.jsxfiles in the provided repository root.\n - Boundary markers: The dry-run report generated by
scripts/report.shuses markdown tables and escapes pipe characters to maintain structural integrity.\n - Capability inventory: The skill is capable of modifying files via
jscodeshiftand executing shell commands via the configured verification scripts.\n - Sanitization: Extracted code snippets are truncated to a maximum of 120 characters to minimize the amount of external content displayed in the report.
Audit Metadata