setup-flows-auth

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for project migration and setup. It performs legitimate modifications to React application files to integrate authentication services.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the installation of several packages. The core libraries (@cognite/app-sdk, @cognite/dune, @cognite/sdk) are official vendor resources. Other dependencies like @tanstack/react-query and vite-plugin-mkcert are widely-used, reputable community packages in the web development ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local configuration files (app.json, package.json) and source code (main.tsx) to determine setup steps.
  • Ingestion points: Reads app.json, package.json, and source files like main.tsx and App.tsx to detect existing auth patterns.
  • Boundary markers: No explicit delimiter markers are used when reading these files into the context.
  • Capability inventory: The skill uses Bash for dependency installation and Edit/Write tools to modify configuration and source code.
  • Sanitization: No specific sanitization or validation of the input file content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:14 PM