react-devtools
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill introduces a potential indirect prompt injection surface by processing external, runtime data from active applications.
- Ingestion points: Untrusted application data, including component display names, prop values, state keys, and hooks, are loaded into the agent context via inspection commands like
agent-react-devtools get treeandagent-react-devtools get componentdefined inSKILL.mdandreferences/commands.md. - Boundary markers: Absent. There are no specific delimiters or system instructions ensuring that the agent treats text inside props, state, or hook values purely as data rather than instructions.
- Capability inventory: The skill holds execution capabilities via the allowed
Bash(agent-react-devtools:*)tool to manage the devtools daemon and query application status. - Sanitization: Ingested prop and state values exceeding 60 characters are automatically truncated as noted in
SKILL.md, which limits the payload size but does not filter out potential prompt injection strings or command structures.
Audit Metadata