reactflow-expert

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and visualization of data from external sources, creating a potential surface for indirect instructions to enter the agent context.
  • Ingestion points: Untrusted data is retrieved via WebSocket streams and API calls integrated into the Zustand useDAGStore and useDAGStream components in SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters or data framing that would instruct the agent to disregard instructions embedded within the visualized node data.
  • Capability inventory: The skill context grants access to powerful tools including Bash, Write, Edit, Grep, and Glob (as defined in SKILL.md frontmatter).
  • Sanitization: The implementation in SKILL.md performs character-length truncation on agent output summaries but lacks deeper sanitization or escaping to prevent the rendering of malicious payloads that might be interpreted by the agent during UI inspection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 06:49 AM
Security Audit — agent-trust-hub — reactflow-expert