typescript-pro

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run standard development commands such as tsc --noEmit for type checking and npx @typescript/analyze-trace for performance profiling. These are benign and necessary for the stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a specialist for processing user-supplied TypeScript codebases, which is a potential surface for indirect injection.
  • Ingestion points: User-supplied source code and project configuration files.
  • Boundary markers: No specific delimiters or warnings are used to differentiate user content from agent instructions.
  • Capability inventory: Shell execution of the TypeScript compiler and performance analysis tools.
  • Sanitization: No explicit sanitization or validation of project data is performed prior to analysis.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to documentation hosted at jeffallan.github.io. This is a vendor-owned resource matching the author's GitHub identity and is used for documentation purposes.
  • [SAFE]: Automated scanner alerts (URLite Blacklist and FileRepMalware) were investigated. Manual inspection of the skill's markdown files and code examples revealed no evidence of malware, obfuscation, or data exfiltration, suggesting the alerts are likely false positives triggered by technical code snippets.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 14, 2026, 08:27 PM
Security Audit — agent-trust-hub — typescript-pro