react-app-scaffold-and-runtime
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute production builds and smoke tests (e2e) using the local package manager. These commands are standard for development workflows and are used here to verify the generated scaffold's integrity.
- [PROMPT_INJECTION]: The skill ingests data from external documents such as 'frontend-architecture.md' and 'architecture/security' to guide the scaffolding process. This represents an indirect prompt injection surface where instructions embedded in those documents could attempt to influence the agent's behavior. The skill includes protective measures like directory verification and adherence to strict security standards to mitigate potential misuse.
Audit Metadata