typescript-expert
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands for environment detection and project validation.
- Evidence: Use of
bunx tsc,node -v, andbun run typecheckinSKILL.mdto interact with the local development environment. - Evidence: The
scripts/ts_diagnostic.pyscript executes system commands includingnpx tsc,grep, andwcusingsubprocess.run. - [DYNAMIC_EXECUTION]: The skill utilizes dynamic code execution for diagnostic purposes.
- Evidence: In
SKILL.md, anode -ecommand is used to execute inline JavaScript that parsespackage.jsonto detect the tooling ecosystem. - Evidence:
scripts/ts_diagnostic.pyusessubprocess.run(shell=True), which allows for shell-interpreted command execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project data, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads
package.json,tsconfig.json, and project source files (viagrepand direct file reads inSKILL.mdandscripts/ts_diagnostic.py). - Boundary markers: Absent; there are no explicit delimiters or instructions to the model to treat the content of these files as untrusted.
- Capability inventory: The skill can execute shell commands (
tsc,vitest,grep,node,bun), read files, and analyze project structure. - Sanitization: Absent; the skill does not sanitize or validate the content of the project files before processing them or using them to inform subsequent agent actions.
Audit Metadata