duplicate-js

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it instructs the agent to analyze untrusted external codebase data (routes, assets, and loading behavior) to identify duplicates.
  • Ingestion points: Reviewing external project assets and network waterfall data as described in SKILL.md and references/rule.md.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' directives for processed data.
  • Capability inventory: No direct script execution or automated capabilities are included; the skill relies on advisory actions and external tool verification (Lighthouse, npm).
  • Sanitization: Absent; no validation or sanitization requirements for the analyzed codebase content are mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:58 PM
Security Audit — agent-trust-hub — duplicate-js