leetcode-coach
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@tiny-fish/cliNode.js package to enable core functionality. This is a legitimate utility provided by the skill's vendor. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from external coding websites, creating a potential surface for indirect prompt injection.
- Ingestion points: Problem metadata and descriptions are fetched from external URLs via the
tinyfish agent runcommand inSKILL.md. - Boundary markers: The agent instructions for data extraction include "STRICT RULES" and output formatting requirements to constrain the agent's behavior.
- Capability inventory: The skill can execute vendor CLI commands and write Markdown and source code files to the local working directory.
- Sanitization: The skill relies on structured JSON output from the extraction tool and uses predefined templates for file creation, which limits the impact of potentially malicious content within the fetched problem descriptions.
Audit Metadata