NYC

typescript-write

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection (LOW): The skill is designed to ingest and refactor external code, which introduces a potential surface for instructions embedded in data. 1. Ingestion points: TypeScript and JavaScript code provided for refactoring as per the skill description. 2. Boundary markers: No delimiters or explicit 'ignore instructions' warnings are present in the provided SKILL.md. 3. Capability inventory: Implied capability to perform filesystem write operations for code generation and refactoring. 4. Sanitization: No sanitization or escaping of external content is defined in the instruction files.
  • No Code (SAFE): The provided files contain markdown documentation and metadata only, with no executable scripts, binaries, or automated command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:26 PM