typescript-patterns

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no executable code or scripts. It consists entirely of natural language instructions (English and Traditional Chinese) directing the AI agent on how to review and improve TypeScript code.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No network tools or external data transfer mechanisms are requested or used. The skill only interacts with standard project configuration files like tsconfig.json and source code files to provide feedback.
  • [PROMPT_INJECTION]: The instructions are clearly defined and do not attempt to bypass safety filters or override system-level constraints. It explicitly includes a rule to treat analyzed code as data rather than instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted user-provided TypeScript code (Category 8 surface), it lacks the capabilities (such as file-writing, network access, or command execution) to be exploited. The output is limited to a text-based review report for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — typescript-patterns