react

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends the use of npx frontend-standard-skills to automate the installation of rules and configuration. This is a standard delivery mechanism for developer tools and is consistent with the author's identified resources.
  • [PROMPT_INJECTION]: The skill is designed to review and analyze source code, which serves as an ingestion point for untrusted data. This creates a surface for indirect prompt injection, as malicious instructions hidden in code comments could attempt to influence the agent's feedback.
  • Ingestion points: User-provided source files (e.g., components in src/components/, hooks in src/hooks/).
  • Boundary markers: The instructions do not specify explicit delimiters to isolate the analyzed code from the agent's logic.
  • Capability inventory: The skill allows the agent to read project files, write rule sets (assets/RULES.md), and perform textual analysis of code.
  • Sanitization: No explicit sanitization or filtering of external source code is defined within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 10:14 PM
Security Audit — agent-trust-hub — react