leetcode-coach

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @tiny-fish/cli Node.js package to enable core functionality. This is a legitimate utility provided by the skill's vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from external coding websites, creating a potential surface for indirect prompt injection.
  • Ingestion points: Problem metadata and descriptions are fetched from external URLs via the tinyfish agent run command in SKILL.md.
  • Boundary markers: The agent instructions for data extraction include "STRICT RULES" and output formatting requirements to constrain the agent's behavior.
  • Capability inventory: The skill can execute vendor CLI commands and write Markdown and source code files to the local working directory.
  • Sanitization: The skill relies on structured JSON output from the extraction tool and uses predefined templates for file creation, which limits the impact of potentially malicious content within the fetched problem descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:04 AM
Security Audit — agent-trust-hub — leetcode-coach