NYC

biome-configuration

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection (SAFE): The skill processes project configuration files as its primary function. While this is a data ingestion surface, it is standard for its purpose and contains no instructions that attempt to override agent behavior.
  • External Downloads (SAFE): The skill references official @biomejs/biome packages and schema URLs from biomejs.dev. These are trustworthy sources for the stated purpose.
  • Command Execution (SAFE): Shell commands provided (npm install, npx biome) are standard for JavaScript/TypeScript development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:13 PM