preen-typescript
Pass
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
rgto find type safety issues and usespnpmandgitfor validation and repository management. These actions are standard for development workflows and restricted to the local filesystem. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it reads and processes local source code which could contain malicious instructions designed to influence the agent's refactoring behavior.
- Ingestion points: Results of
rgcommands on local TypeScript files in SKILL.md. - Boundary markers: Absent in the refactoring workflow.
- Capability inventory: File write access, execution of
pnpm, andgitrepository management. - Sanitization: No sanitization is performed on the code content before analysis.
Audit Metadata