typescript-pro
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external documentation URL
https://jeffallan.github.io/claude-skills/skills/language/typescript-pro/. Automated scanners (URLite) have flagged this domain and specific path as malicious and blacklisted.\n- [COMMAND_EXECUTION]: The skill workflow and reference guides instruct the agent to execute shell commands, specificallytsc --noEmitfor type checking andnpx @typescript/analyze-tracefor trace analysis. While common in development, these represent system-level command execution capabilities.\n- [METADATA_POISONING]: TheSKILL.mdfile was identified by reputation scanners (FileRepMalware), indicating the presence of metadata or content signatures associated with known malicious activity. Additionally, the author listed in the file (Jeffallan) does not match the provided author context (sodiqabdulwaris).
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata