upgrade-rspack

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes pnpm build, pnpm test, and pnpm e2e to validate the Rspack upgrade. These commands are standard for continuous integration and development workflows within the intended use case.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted data from the repository environment.
  • Ingestion points: Reads content from pnpm-workspace.yaml, .github/PULL_REQUEST_TEMPLATE.md, and output logs from build/test commands.
  • Boundary markers: None explicitly defined for the ingested file content.
  • Capability inventory: Can modify local files (pnpm-workspace.yaml), execute shell commands (pnpm build/test/e2e, pnpm update), and interact with GitHub (gh CLI) to create pull requests.
  • Sanitization: No specific sanitization or validation of the ingested repository files is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:52 PM
Security Audit — agent-trust-hub — upgrade-rspack