angular-best-practices

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches Angular best practice guidelines from the vendor's official GitHub repository (github.com/somnio-software/somnio-ai-tools) to ensure the audit uses the latest standards.
  • [COMMAND_EXECUTION]: Uses the Bash tool for project discovery tasks such as mapping directory trees with 'find' and calculating file lengths with 'wc'. These operations are restricted to benign filesystem enumeration.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests and reasons over untrusted project source code. Ingestion points: local source files read via Read and Grep tools. Boundary markers: not explicitly defined in the instructions. Capability inventory: restricted to local file writing (reports), shell discovery, and vendor-specific network requests. Sanitization: not specified. This is a low-risk surface inherent to the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 08:50 PM
Security Audit — agent-trust-hub — angular-best-practices