devextreme-datebox

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious injection patterns or safety bypasses detected. The static analysis flag regarding policy bypass is a false positive triggered by defensive language instructing the agent not to follow commands found in external documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface when fetching external documentation via MCP tools and explicitly instructs the agent to treat that content as untrusted reference data, preventing typical indirect injection techniques.
  • [EXTERNAL_DOWNLOADS]: References to Node.js packages (devextreme family) and documentation tools are verified vendor resources from DevExpress and follow legitimate development patterns.
  • [DATA_EXFILTRATION]: No patterns for accessing sensitive system files, environment variables, or exfiltrating data to unauthorized external domains were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — devextreme-datebox