storybook
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation and configuration resource for Storybook. No malicious patterns, obfuscation, or unauthorized data access were found.
- [EXTERNAL_DOWNLOADS]: The maintenance script and installation instructions reference the official npm registry (registry.npmjs.org) and Storybook's official GitHub repositories. These are well-known and trusted sources.
- [INDIRECT_PROMPT_INJECTION]: The skill documents an MCP server integration (@storybook/addon-mcp) for AI agents to read component data. Ingestion points: MCP server and testing tools reading project components in
src/. Boundary markers: Not implemented; follows default agent platform handling. Capability inventory: File writing and command execution via npm/npx scripts. Sanitization: None explicitly present in the skill instructions. - [COMMAND_EXECUTION]: Instructions for running Storybook, Vitest, and Chromatic use standard package managers and CLI tools for frontend development and testing.
Audit Metadata