Security audit
typescript-dev
Security checks across malware telemetry and agentic risk
Overview
This is a coherent markdown guidance skill for TypeScript app development; it has no hidden execution, persistence, or data-exfiltration behavior, though some optional tooling commands can modify a project when the user invokes them.
Install only if you want an agent to follow opinionated modern TypeScript stack guidance. Review diffs after commands like shadcn add, biome check --write, migrations, or deployment examples, because they can legitimately change project files or publish code when you ask the agent to run them.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
