react-expert
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform code validation by running the command
tsc --noEmit. This is a routine task for a software development assistant to ensure type safety in projects. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-supplied React code and project requirements, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: The skill ingests component definitions, state management requirements, and architectural designs provided within the conversation context (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters defined to separate user-provided code from the agent's internal instructions or to ignore embedded commands.
- Capability inventory: The agent is encouraged to run validation tools like
tscand suggest testing strategies using frameworks such as Vitest or Jest (references/testing-react.md). - Sanitization: The instructions lack specific procedures for sanitizing or escaping content retrieved from project files before processing.
Audit Metadata