skills/pproenca/dot-skills/ts-google/Gen Agent Trust Hub

ts-google

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to trigger on TypeScript files, type annotations, and module imports to guide refactoring and code review, creating a surface for indirect prompt injection. Malicious actors could embed instructions in comments or string literals within the code being analyzed to manipulate the agent's behavior during these tasks.
  • Ingestion points: TypeScript source files (.ts) and project configuration files processed by the agent.
  • Boundary markers: The skill does not establish specific boundary markers or "ignore" instructions for the untrusted code it processes.
  • Capability inventory: Agents applying these rules typically have access to the file system to read and refactor code, and may have access to terminal tools for build verification.
  • Sanitization: The skill provides stylistic rules but lacks mechanisms to sanitize or filter out linguistic instructions that might be present in the target codebases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:49 AM
Security Audit — agent-trust-hub — ts-google