gleam-javascript-interop

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Gleam documentation (gleam.run) and package registries (hexdocs.pm). These are well-known, trusted sources within the Gleam ecosystem and do not pose a security risk.
  • [COMMAND_EXECUTION]: Includes standard development commands for building, running, and testing Gleam projects targeting JavaScript, such as 'gleam build', 'gleam test', and 'node'. These are necessary for the skill's stated purpose.
  • [REMOTE_CODE_EXECUTION]: While the skill explains how to use Foreign Function Interface (FFI) and integrate with NPM packages, it provides explicit warnings about the risks involved. It mandates comprehensive unit testing and wrapping external calls in safe Gleam APIs to mitigate runtime errors and type mismatches.
  • [PROMPT_INJECTION]: No patterns for prompt injection, behavior overrides, or safety filter bypasses were detected in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:27 PM
Security Audit — agent-trust-hub — gleam-javascript-interop