javascript-pro
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Automated security analysis tools have identified components of this skill as malicious.\n
- The URL
https://jeffallan.github.io/claude-skills/skills/language/javascript-pro/is currently blacklisted by security reputation providers.\n - The file
SKILL.mdis flagged with a malicious reputation (FileRepMalware [Misc]) by file reputation scanners.\n- [EXTERNAL_DOWNLOADS]: The skill instructs agents to reference external resources on a domain (jeffallan.github.io) that is currently associated with malicious activity, potentially leading to the execution of untrusted logic or instructions.\n- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of external source code without sufficient isolation or sanitization.\n - Ingestion points: The skill is designed to read and analyze
.js,.mjs,.cjs, andpackage.jsonfiles.\n - Boundary markers: There are no instructions to use delimiters or ignore instructions embedded in the processed files, which could lead to an agent following malicious commands hidden in code comments or strings.\n
- Capability inventory: The skill documentation provides examples and instructions for using powerful system capabilities, including network requests (
fetch), file system access (fs/promises), and subprocess execution (child_process.spawn,exec).\n - Sanitization: The skill lacks any requirement or mechanism to validate or sanitize external file content before it is incorporated into the agent's context.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata