code-change-verification

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development commands (e.g., npm run build, npm test, npx mocha, npx tsd) and project-specific scripts (node bin/index.js). These are necessary for validating TypeScript changes, regenerating command support files, and running functional test suites within the local development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading git diff outputs and source code files (e.g., lib/, test/). While these files represent an external data ingestion surface, the skill limits the agent's actions to specific, non-destructive validation commands. There is no evidence of instructions that would lead to unauthorized data exfiltration or safety bypasses.
  • [EXTERNAL_DOWNLOADS]: The workflow mentions npm run docker:setup, which is the standard method for provisioning local Redis testing infrastructure for the ioredis library. This involves pulling official Redis Docker images, which is expected behavior for a database client development tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:42 PM
Security Audit — agent-trust-hub — code-change-verification