devextreme-datebox
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No malicious injection patterns or safety bypasses detected. The static analysis flag regarding policy bypass is a false positive triggered by defensive language instructing the agent not to follow commands found in external documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface when fetching external documentation via MCP tools and explicitly instructs the agent to treat that content as untrusted reference data, preventing typical indirect injection techniques.
- [EXTERNAL_DOWNLOADS]: References to Node.js packages (devextreme family) and documentation tools are verified vendor resources from DevExpress and follow legitimate development patterns.
- [DATA_EXFILTRATION]: No patterns for accessing sensitive system files, environment variables, or exfiltrating data to unauthorized external domains were found.
Audit Metadata