scan-nest-features
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to run the
greputility to find specific symbol locations within the localnode_modulesdirectory.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external package files, establishing a surface for indirect prompt injection.\n - Ingestion points: Files located at
node_modules/@nestjs/*/dist/*.d.ts(SKILL.md Step 1).\n - Boundary markers: None specified to prevent the agent from following instructions embedded in the scanned files.\n
- Capability inventory: File system read access and command execution via
grep.\n - Sanitization: No validation or sanitization of the scanned file content is performed.
Audit Metadata