bestax-custom-component
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No malicious injection patterns or safety bypass attempts were found. The skill instructions focus strictly on React component development and composition using the Bestax library.
- [DATA_EXFILTRATION]: No evidence of sensitive file access or unauthorized data exfiltration. All referenced domains (bestax.io) and packages (@allxsmith/bestax-bulma) belong to the skill vendor.
- [OBFUSCATION]: Analysis of the skill body and code examples revealed no hidden content, Base64 encoding, zero-width characters, or homoglyph attacks.
- [REMOTE_CODE_EXECUTION]: The skill does not perform or suggest any remote script execution via curl/wget piping to a shell. Build and development commands described (npm run dev, pnpm build) are appropriate for the skill's purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection surface through code generation:
- Ingestion points: User descriptions of custom React components in SKILL.md.
- Boundary markers: Not present.
- Capability inventory: File writing and local command execution for builds/tests.
- Sanitization: Not present; relies on the agent's internal safety filters and user review of generated output.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic context injection (!
command) to execute shell commands during loading.
Audit Metadata