husky-test-coverage
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project configuration files and incorporates it into a generated shell script without sanitization.
- Ingestion points: The script
scripts/setup-husky-coverage.pyreads data frompackage.json(specifically thetestscript and dependencies),.husky-test-coverage.json, and various test runner configuration files (e.g.,jest.config.json). - Boundary markers: There are no delimiters or explicit warnings to the agent to ignore instructions embedded within the ingested configuration files.
- Capability inventory: The skill uses
subprocess.run()to perform package installations andPath.write_text()to create executable scripts. - Sanitization: The value of the project's
testscript is interpolated directly into the.husky/pre-commithook file, meaning a malicious script inpackage.jsonwould be automatically included in the generated hook. - [COMMAND_EXECUTION]: The skill uses the Python
subprocessmodule to manage environment setup and dependency installation. - Evidence: The
run_commandfunction inscripts/setup-husky-coverage.pyexecutes commands such asnpm install,bun add, andnpx husky install. The implementation follows best practices by passing arguments as a list rather than a single shell string, mitigating direct command injection risks during the setup phase. - [PRIVILEGE_ESCALATION]: The skill modifies file system permissions to ensure the functionality of the generated git hooks.
- Evidence: In
scripts/setup-husky-coverage.py, the code callspre_commit_path.chmod(0o755)on the newly created hook file. This elevates the file's permissions to allow execution, which is the intended behavior for a Husky hook but represents the creation of a new executable entry point in the repository.
Audit Metadata