storybook

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical guide for Storybook 10 development, focusing on configuration, story authoring, and testing workflows.
  • [EXTERNAL_DOWNLOADS]: The instructions involve using bunx to download and execute official Storybook CLI tools and Playwright browser binaries. These operations target the official npm registry and well-known browser distribution channels.
  • [COMMAND_EXECUTION]: The skill guides the agent to perform standard development tasks such as building the Storybook workshop, running diagnostics, and executing Vitest tests. These commands are necessary for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local project files like package.json, .storybook/main.ts, and component stories. While this creates a surface for indirect prompt injection if external data is present in those files, the instructions prioritize established project structures and official Storybook practices, which is typical for development-oriented agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:59 PM
Security Audit — agent-trust-hub — storybook