kahraman-storybook-testing
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it directs the agent to read and process content from external GitHub repositories and local project files.\n
- Ingestion points: External configuration examples at
github.com/guria/modern-stackandgithub.com/reatom/reatom, as well as local.storybookdirectory contents.\n - Boundary markers: The skill contains warnings to treat external content as references only and not to copy aliases or commands blindly, though it lacks explicit technical delimiters for this data.\n
- Capability inventory: The agent possesses
Bashtools for reading, editing, and writing files, which could be misused if malicious instructions are encountered in processed data.\n - Sanitization: No specific sanitization or validation steps are defined for the content retrieved from these sources.\n- [EXTERNAL_DOWNLOADS]: The instructions direct the agent to access and analyze external configuration files from third-party GitHub repositories to establish testing patterns.
Audit Metadata