rescript
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructional content for ReScript development, including language syntax, interop bindings, and React integration. No malicious code or hidden functionality was detected.
- [SAFE]: All command-line examples and package recommendations (e.g.,
npx create-rescript-app,npm install rescript, andrescript-jest) refer to official or established tools in the ReScript ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided code and compiler errors (ingestion points in
SKILL.md), creating a surface for indirect prompt injection. Boundary markers are absent. The capability inventory is empty as the skill does not invoke any tools or dangerous subprocesses. Sanitization is absent, but the lack of exploitable capabilities results in a safe assessment.
Audit Metadata