scan-nest-features

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to run the grep utility to find specific symbol locations within the local node_modules directory.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external package files, establishing a surface for indirect prompt injection.\n
  • Ingestion points: Files located at node_modules/@nestjs/*/dist/*.d.ts (SKILL.md Step 1).\n
  • Boundary markers: None specified to prevent the agent from following instructions embedded in the scanned files.\n
  • Capability inventory: File system read access and command execution via grep.\n
  • Sanitization: No validation or sanitization of the scanned file content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 11:50 PM
Security Audit — agent-trust-hub — scan-nest-features