typescript-pro

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external documentation URL https://jeffallan.github.io/claude-skills/skills/language/typescript-pro/. Automated scanners (URLite) have flagged this domain and specific path as malicious and blacklisted.\n- [COMMAND_EXECUTION]: The skill workflow and reference guides instruct the agent to execute shell commands, specifically tsc --noEmit for type checking and npx @typescript/analyze-trace for trace analysis. While common in development, these represent system-level command execution capabilities.\n- [METADATA_POISONING]: The SKILL.md file was identified by reputation scanners (FileRepMalware), indicating the presence of metadata or content signatures associated with known malicious activity. Additionally, the author listed in the file (Jeffallan) does not match the provided author context (sodiqabdulwaris).
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — typescript-pro