duplicate-js
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it instructs the agent to analyze untrusted external codebase data (routes, assets, and loading behavior) to identify duplicates.
- Ingestion points: Reviewing external project assets and network waterfall data as described in SKILL.md and references/rule.md.
- Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' directives for processed data.
- Capability inventory: No direct script execution or automated capabilities are included; the skill relies on advisory actions and external tool verification (Lighthouse, npm).
- Sanitization: Absent; no validation or sanitization requirements for the analyzed codebase content are mentioned.
Audit Metadata