hig-doctor-audit

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and execute a specific version of the hig-doctor package (2.0.3) from the npm registry. This is required to perform the requested interface and accessibility audits.
  • [COMMAND_EXECUTION]: The skill performs shell command execution through npx to scan directories, generate JSON reports, and manage baseline configuration files within the target repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local source code across multiple frameworks (Swift, React, Flutter, etc.). This represents a surface where untrusted data within the files being audited could attempt to influence the agent's output.
  • Ingestion points: The skill reads source code and interface files from the user-specified target directory as defined in the SKILL.md audit workflow.
  • Boundary markers: There are no specific delimiters defined for the source code content being processed, although findings are returned in a structured JSON format.
  • Capability inventory: The agent has the capability to run shell commands via npx and perform file system writes for remediation tasks as described in the workflow.
  • Sanitization: The instructions do not specify sanitization or filtering of the source code content before it is processed by the AI for review or remediation recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:14 AM
Security Audit — agent-trust-hub — hig-doctor-audit