Typescript Project Standard

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only TypeScript standards skill with no executable code, persistence, credential access, or hidden data movement.

Install if you want an agent to apply TypeScript project standards across tsconfig, type boundaries, public APIs, and declaration packaging. Be aware it may trigger for many TypeScript-related requests, so use a more specific framework skill when the task is mainly React, Vue, Next, Nuxt, routing, or state architecture.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description is extremely broad and includes many common TypeScript tasks such as creating, reviewing, debugging, tsconfig work, generics, and type safety. In an agentic skill-selection system, this can cause the skill to be invoked for a very wide range of ordinary TypeScript requests, increasing the chance of overreach, unintended instruction injection from the skill, or routing away from a more specific and safer skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal