controlled-uncontrolled
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of markdown-based instructions and code examples for analyzing React component patterns. The instructions focus on best practices for frontend development, specifically handling React's value and defaultValue props. No evidence of command execution, credential harvesting, or unauthorized data access was found.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing external React source code. (1) Ingestion points: The skill instructions in Step 1 (Scan the codebase) involve reading untrusted user-provided code. (2) Boundary markers: None explicitly defined in the skill text for the ingested code. (3) Capability inventory: The skill is limited to generating text-based audit reports and refactored code snippets; it does not request or use tools for file system writes, network requests, or shell execution. (4) Sanitization: Not applicable as the output is intended for human review.
Audit Metadata