ultracite

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests running 'npx ultracite', which downloads the package from the NPM registry. This is consistent with its role as a CLI-based code quality tool.
  • [COMMAND_EXECUTION]: The skill defines specific commands for project initialization and code remediation using the npx runner.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads and modifies external codebases. 1. Ingestion points: Project files accessed via the Read tool. 2. Boundary markers: Absent; there are no instructions to disregard instructions within the analyzed code. 3. Capability inventory: Read, Grep, Glob, and Edit. 4. Sanitization: Absent; the skill does not specify any pre-processing or validation of the code content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 08:00 AM
Security Audit — agent-trust-hub — ultracite