forms-and-validation
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains standard development instructions and best practices for React form handling. No malicious patterns, obfuscation, or unauthorized data exfiltration were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes user-provided form requirements to generate code.
- Ingestion points: User-provided form specifications and component code in SKILL.md.
- Boundary markers: Absent.
- Capability inventory: Modifies files within the repository using the repo-files tool.
- Sanitization: Absent.
- [DATA_EXPOSURE]: The skill implements a security best practice by explicitly instructing the agent not to access or edit .env files, reducing the risk of accidental credential exposure.
Audit Metadata