local-vs-global-state
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided React components, file trees, and verbal descriptions of application state, which constitutes an untrusted data ingestion surface.\n
- Ingestion points: User-provided components and descriptions as defined in
SKILL.md.\n - Boundary markers: The instructions do not define specific delimiters or guardrails for the user-supplied data.\n
- Capability inventory: No dangerous capabilities such as file system writes, shell command execution, or network operations were found in any files.\n
- Sanitization: There are no explicit instructions to sanitize or escape the user-provided data before processing.
Audit Metadata