nuqs-codemod-runner

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates several system utilities and local project scripts to analyze and modify the codebase.\n
  • Utilizes ripgrep (rg) for high-performance pattern matching and jq for manipulating JSON data in scripts/scan.sh and scripts/apply.sh.\n
  • Uses git across multiple scripts to validate the repository's clean state, parse the current HEAD, and perform file restorations in case of failure.\n
  • Employs python3 for date calculations to ensure scan data remains fresh before application.\n
  • Executes project-specific verification commands, such as npm run lint and npx tsc, using eval within scripts/verify.sh.\n- [EXTERNAL_DOWNLOADS]: The skill uses well-known package runners to fetch standard tools from official registries.\n
  • scripts/apply.sh invokes npx --yes jscodeshift@latest to obtain the migration tool from the npm registry.\n
  • scripts/verify.sh invokes npx tsc (depending on configuration) to run type-checking.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface that processes untrusted local source code, which is then summarized in a report for the agent and user.\n
  • Ingestion points: scripts/scan.sh reads code from .ts, .tsx, .js, and .jsx files in the provided repository root.\n
  • Boundary markers: The dry-run report generated by scripts/report.sh uses markdown tables and escapes pipe characters to maintain structural integrity.\n
  • Capability inventory: The skill is capable of modifying files via jscodeshift and executing shell commands via the configured verification scripts.\n
  • Sanitization: Extracted code snippets are truncated to a maximum of 120 characters to minimize the amount of external content displayed in the report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:49 AM
Security Audit — agent-trust-hub — nuqs-codemod-runner