javascript-pro

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Automated security scanners have identified the documentation URL https://jeffallan.github.io/claude-skills/skills/language/javascript-pro/ in SKILL.md as malicious (URL:Blacklist). This link points to a user-controlled GitHub Pages site which is flagged as a threat.
  • [COMMAND_EXECUTION]: The reference file references/node-essentials.md provides detailed instructions and code examples for executing shell commands through Node.js using child_process.exec and child_process.spawn. This capability allows the skill to interact directly with the underlying operating system.
  • [DATA_EXFILTRATION]: The reference documentation describes full access to the local file system using the fs/promises module and the ability to perform network operations using the fetch API. The presence of both read and send capabilities creates a significant data exfiltration risk, especially given the malicious reputation findings for the skill's source and external links.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — javascript-pro