hig-doctor-audit
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto download and execute a specific version of thehig-doctorpackage (2.0.3) from the npm registry. This is required to perform the requested interface and accessibility audits. - [COMMAND_EXECUTION]: The skill performs shell command execution through
npxto scan directories, generate JSON reports, and manage baseline configuration files within the target repository. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes local source code across multiple frameworks (Swift, React, Flutter, etc.). This represents a surface where untrusted data within the files being audited could attempt to influence the agent's output.
- Ingestion points: The skill reads source code and interface files from the user-specified target directory as defined in the SKILL.md audit workflow.
- Boundary markers: There are no specific delimiters defined for the source code content being processed, although findings are returned in a structured JSON format.
- Capability inventory: The agent has the capability to run shell commands via
npxand perform file system writes for remediation tasks as described in the workflow. - Sanitization: The instructions do not specify sanitization or filtering of the source code content before it is processed by the AI for review or remediation recommendations.
Audit Metadata