upgrade-rspack
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
pnpm build,pnpm test, andpnpm e2eto validate the Rspack upgrade. These commands are standard for continuous integration and development workflows within the intended use case. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted data from the repository environment.
- Ingestion points: Reads content from
pnpm-workspace.yaml,.github/PULL_REQUEST_TEMPLATE.md, and output logs from build/test commands. - Boundary markers: None explicitly defined for the ingested file content.
- Capability inventory: Can modify local files (
pnpm-workspace.yaml), execute shell commands (pnpm build/test/e2e,pnpm update), and interact with GitHub (ghCLI) to create pull requests. - Sanitization: No specific sanitization or validation of the ingested repository files is mentioned.
Audit Metadata