react-expert

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The YAML frontmatter identifies the author as 'https://github.com/Jeffallan', which is inconsistent with the provided skill owner '1git2clone'. This is likely a legacy artifact from a forked or templated repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided architectural requirements and code snippets to generate React components and hooks.
  • Ingestion points: User-supplied project requirements, component specifications, and legacy class components for migration (SKILL.md and migration reference).
  • Boundary markers: Absent. The instructions do not define explicit delimiters or include safety warnings to ignore instructions embedded in user-supplied documentation or code.
  • Capability inventory: The skill is capable of generating source code, running the TypeScript compiler (tsc --noEmit), and executing automated tests.
  • Sanitization: No input validation or sanitization is specified for external data processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — react-expert