migrate-to-shoehorn

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @total-typescript/shoehorn package via npm. This is a standard dependency for the migration's intended purpose and comes from a well-known community source.
  • [COMMAND_EXECUTION]: The skill uses grep to identify specific code patterns within the project's test files. This is a standard local search operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it reads and processes user-controlled test files (*.test.ts, *.spec.ts). However, the risk is minimal as the instructions are focused on specific code transformations (replacing as assertions) and package installation, rather than executing the contents of those files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:22 PM
Security Audit — agent-trust-hub — migrate-to-shoehorn