storybook

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation and configuration resource for Storybook. No malicious patterns, obfuscation, or unauthorized data access were found.
  • [EXTERNAL_DOWNLOADS]: The maintenance script and installation instructions reference the official npm registry (registry.npmjs.org) and Storybook's official GitHub repositories. These are well-known and trusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an MCP server integration (@storybook/addon-mcp) for AI agents to read component data. Ingestion points: MCP server and testing tools reading project components in src/. Boundary markers: Not implemented; follows default agent platform handling. Capability inventory: File writing and command execution via npm/npx scripts. Sanitization: None explicitly present in the skill instructions.
  • [COMMAND_EXECUTION]: Instructions for running Storybook, Vitest, and Chromatic use standard package managers and CLI tools for frontend development and testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — storybook