reactflow-expert
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and visualization of data from external sources, creating a potential surface for indirect instructions to enter the agent context.
- Ingestion points: Untrusted data is retrieved via WebSocket streams and API calls integrated into the Zustand
useDAGStoreanduseDAGStreamcomponents inSKILL.md. - Boundary markers: The instructions do not define clear delimiters or data framing that would instruct the agent to disregard instructions embedded within the visualized node data.
- Capability inventory: The skill context grants access to powerful tools including
Bash,Write,Edit,Grep, andGlob(as defined inSKILL.mdfrontmatter). - Sanitization: The implementation in
SKILL.mdperforms character-length truncation on agent output summaries but lacks deeper sanitization or escaping to prevent the rendering of malicious payloads that might be interpreted by the agent during UI inspection.
Audit Metadata