bestax-custom-component

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious injection patterns or safety bypass attempts were found. The skill instructions focus strictly on React component development and composition using the Bestax library.
  • [DATA_EXFILTRATION]: No evidence of sensitive file access or unauthorized data exfiltration. All referenced domains (bestax.io) and packages (@allxsmith/bestax-bulma) belong to the skill vendor.
  • [OBFUSCATION]: Analysis of the skill body and code examples revealed no hidden content, Base64 encoding, zero-width characters, or homoglyph attacks.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform or suggest any remote script execution via curl/wget piping to a shell. Build and development commands described (npm run dev, pnpm build) are appropriate for the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection surface through code generation:
  • Ingestion points: User descriptions of custom React components in SKILL.md.
  • Boundary markers: Not present.
  • Capability inventory: File writing and local command execution for builds/tests.
  • Sanitization: Not present; relies on the agent's internal safety filters and user review of generated output.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic context injection (!command) to execute shell commands during loading.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:36 PM
Security Audit — agent-trust-hub — bestax-custom-component