setup-ts-deep-modules
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies the project environment and merges configuration rules by reading untrusted local files, which presents a surface for indirect prompt injection.
- Ingestion points: Reads project files including
package.json, repository lockfiles (pnpm-lock.yaml,yarn.lock,bun.lockb),tsconfig.json, and any existing.dependency-cruiser.*configuration files. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the data read from these files.
- Capability inventory: The skill has the capability to execute shell commands via the package manager, write new files (
.dependency-cruiser.cjs,README.md,AGENTS.md), and modify the project'spackage.jsonscripts. - Sanitization: The skill does not perform specific validation or sanitization on the contents of the lockfiles or existing configuration files before using them to drive installation and configuration steps.
- [COMMAND_EXECUTION]: The skill performs shell command execution to manage dependencies and verify the environment setup.
- Evidence: Step 2 executes package manager commands to install
dependency-cruiseras a devDependency. Step 6 executes thedepcruisecommand multiple times to verify that the newly created rules correctly identify and block restricted imports.
Audit Metadata