react-component-performance
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided React source code for diagnosis, creating a surface for instructions embedded in code comments or strings.
- Ingestion points: React component code provided by the user during the workflow.
- Boundary markers: Absent; there are no delimiters or explicit instructions to separate untrusted user code from the agent's internal logic.
- Capability inventory: Low risk; the skill focuses on providing analysis and advice and does not request tool access for shell, network, or file system operations.
- Sanitization: No logic is present to sanitize or filter potential instructions within user-provided code.
- [SAFE]: The skill's content is entirely educational, providing standard React optimization patterns with no evidence of obfuscation, remote code execution, or credential theft.
Audit Metadata