kahraman-storybook-testing

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it directs the agent to read and process content from external GitHub repositories and local project files.\n
  • Ingestion points: External configuration examples at github.com/guria/modern-stack and github.com/reatom/reatom, as well as local .storybook directory contents.\n
  • Boundary markers: The skill contains warnings to treat external content as references only and not to copy aliases or commands blindly, though it lacks explicit technical delimiters for this data.\n
  • Capability inventory: The agent possesses Bash tools for reading, editing, and writing files, which could be misused if malicious instructions are encountered in processed data.\n
  • Sanitization: No specific sanitization or validation steps are defined for the content retrieved from these sources.\n- [EXTERNAL_DOWNLOADS]: The instructions direct the agent to access and analyze external configuration files from third-party GitHub repositories to establish testing patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 11:26 AM
Security Audit — agent-trust-hub — kahraman-storybook-testing