javascript-pro
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Automated security scanners have identified the documentation URL
https://jeffallan.github.io/claude-skills/skills/language/javascript-pro/inSKILL.mdas malicious (URL:Blacklist). This link points to a user-controlled GitHub Pages site which is flagged as a threat. - [COMMAND_EXECUTION]: The reference file
references/node-essentials.mdprovides detailed instructions and code examples for executing shell commands through Node.js usingchild_process.execandchild_process.spawn. This capability allows the skill to interact directly with the underlying operating system. - [DATA_EXFILTRATION]: The reference documentation describes full access to the local file system using the
fs/promisesmodule and the ability to perform network operations using thefetchAPI. The presence of both read and send capabilities creates a significant data exfiltration risk, especially given the malicious reputation findings for the skill's source and external links.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata