reactbits
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by fetching and integrating external source code.
- Ingestion points: The
mcp__reactbits__get_componentandmcp__reactbits__get_component_demotools retrieve component source code and usage examples from ReactBits.dev. - Boundary markers: The skill does not define boundary markers or provide explicit instructions to isolate external content or to ignore potential instructions embedded in the fetched source code.
- Capability inventory: The skill grants the agent the capability to write files to the
components/directory and create CSS files. - Sanitization: No process for sanitizing or validating the code retrieved from the external source is described.
- [EXTERNAL_DOWNLOADS]: The skill fetches component source code and documentation from ReactBits.dev. While this is the primary purpose of the skill, it involves retrieving data from an external, non-whitelisted source.
Audit Metadata