angular-migration
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill references a local utility script
scripts/analyze-angular-app.shintended for the agent to use during the codebase assessment phase. While the script content is not provided, its inclusion is a standard functional element for the stated purpose. - [PROMPT_INJECTION]: The skill instructions (Step 1) require the agent to ingest and assess an external AngularJS codebase. This creates an attack surface for indirect prompt injection where malicious instructions hidden in the source code could influence agent behavior. Ingestion points: Assessment of external AngularJS codebase and dependencies. Boundary markers: No explicit delimiters or instructions to ignore embedded content are provided. Capability inventory: Use of an analysis script and instructions for code migration imply the use of command execution and file modification capabilities. Sanitization: No specific sanitization or filtering of the ingested code is described.
Audit Metadata