local-vs-global-state

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided React components, file trees, and verbal descriptions of application state, which constitutes an untrusted data ingestion surface.\n
  • Ingestion points: User-provided components and descriptions as defined in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters or guardrails for the user-supplied data.\n
  • Capability inventory: No dangerous capabilities such as file system writes, shell command execution, or network operations were found in any files.\n
  • Sanitization: There are no explicit instructions to sanitize or escape the user-provided data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:46 PM
Security Audit — agent-trust-hub — local-vs-global-state