react-devtools

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill introduces a potential indirect prompt injection surface by processing external, runtime data from active applications.
  • Ingestion points: Untrusted application data, including component display names, prop values, state keys, and hooks, are loaded into the agent context via inspection commands like agent-react-devtools get tree and agent-react-devtools get component defined in SKILL.md and references/commands.md.
  • Boundary markers: Absent. There are no specific delimiters or system instructions ensuring that the agent treats text inside props, state, or hook values purely as data rather than instructions.
  • Capability inventory: The skill holds execution capabilities via the allowed Bash(agent-react-devtools:*) tool to manage the devtools daemon and query application status.
  • Sanitization: Ingested prop and state values exceeding 60 characters are automatically truncated as noted in SKILL.md, which limits the payload size but does not filter out potential prompt injection strings or command structures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:36 AM
Security Audit — agent-trust-hub — react-devtools