express-typescript-starter
Fail
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS] (HIGH): The skill fetches content from 'https://github.com/edwinhern/express-typescript.git', which is not a verified or trusted repository within the defined security scope.
- [REMOTE_CODE_EXECUTION] (HIGH): The instructions to run 'npm install' and 'npm run dev' on unverified external code allow for arbitrary command execution via package scripts (e.g., preinstall/postinstall) or malicious dependencies.
Recommendations
- AI detected serious security threats
Audit Metadata