reactbits

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by fetching and integrating external source code.
  • Ingestion points: The mcp__reactbits__get_component and mcp__reactbits__get_component_demo tools retrieve component source code and usage examples from ReactBits.dev.
  • Boundary markers: The skill does not define boundary markers or provide explicit instructions to isolate external content or to ignore potential instructions embedded in the fetched source code.
  • Capability inventory: The skill grants the agent the capability to write files to the components/ directory and create CSS files.
  • Sanitization: No process for sanitizing or validating the code retrieved from the external source is described.
  • [EXTERNAL_DOWNLOADS]: The skill fetches component source code and documentation from ReactBits.dev. While this is the primary purpose of the skill, it involves retrieving data from an external, non-whitelisted source.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 03:03 PM
Security Audit — agent-trust-hub — reactbits