react-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidelines for React development, focusing on modern patterns like Server Components and advanced hooks. No malicious instructions or security bypasses were found.
  • [EXTERNAL_DOWNLOADS]: The metadata includes an installation command that fetches the skill's markdown definition from a public GitHub repository. This is a standard method for skill distribution and utilizes a trusted platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest React project requirements from a context manager to provide architectural advice. While this represents a potential surface for indirect injection (Cat 8), the instructions prioritize standard coding practices and the skill lacks instructions that would lead to dangerous autonomous actions based on that input.
  • [COMMAND_EXECUTION]: The skill defines a set of allowed tools including 'Bash' and 'npm'. These are necessary for its stated purpose as a development specialist and are scoped within the agent's restricted environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:59 AM
Security Audit — agent-trust-hub — react-specialist