react-expert
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The YAML frontmatter identifies the author as 'https://github.com/Jeffallan', which is inconsistent with the provided skill owner '1git2clone'. This is likely a legacy artifact from a forked or templated repository.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided architectural requirements and code snippets to generate React components and hooks.
- Ingestion points: User-supplied project requirements, component specifications, and legacy class components for migration (SKILL.md and migration reference).
- Boundary markers: Absent. The instructions do not define explicit delimiters or include safety warnings to ignore instructions embedded in user-supplied documentation or code.
- Capability inventory: The skill is capable of generating source code, running the TypeScript compiler (
tsc --noEmit), and executing automated tests. - Sanitization: No input validation or sanitization is specified for external data processed by the agent.
Audit Metadata