typescript-strict
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill defines a 'Reference System Usage' that ingests data from local markdown files (e.g.,
references/patterns.md). This is a standard architectural pattern for skills and presents a low risk as it does not involve untrusted remote content or high-privilege execution capabilities. - [Prompt Injection] (SAFE): Instructions are focused on domain expertise (TypeScript). No bypass, override, or system prompt extraction patterns were identified.
- [Data Exfiltration] (SAFE): No network operations or access to sensitive local environment files (credentials, SSH keys) were found.
- [Remote Code Execution] (SAFE): No package managers, remote downloads, or dynamic execution patterns are present in the skill definition.
Audit Metadata