react-component-performance

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided React source code for diagnosis, creating a surface for instructions embedded in code comments or strings.
  • Ingestion points: React component code provided by the user during the workflow.
  • Boundary markers: Absent; there are no delimiters or explicit instructions to separate untrusted user code from the agent's internal logic.
  • Capability inventory: Low risk; the skill focuses on providing analysis and advice and does not request tool access for shell, network, or file system operations.
  • Sanitization: No logic is present to sanitize or filter potential instructions within user-provided code.
  • [SAFE]: The skill's content is entirely educational, providing standard React optimization patterns with no evidence of obfuscation, remote code execution, or credential theft.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:56 AM
Security Audit — agent-trust-hub — react-component-performance