express-typescript-starter

Fail

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (HIGH): The skill fetches content from 'https://github.com/edwinhern/express-typescript.git', which is not a verified or trusted repository within the defined security scope.
  • [REMOTE_CODE_EXECUTION] (HIGH): The instructions to run 'npm install' and 'npm run dev' on unverified external code allow for arbitrary command execution via package scripts (e.g., preinstall/postinstall) or malicious dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 17, 2026, 06:11 PM