emblem-ai-react

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from remote APIs to populate React UI components.
  • Ingestion points: File references/migratefun-react.md describes hooks such as useProject and useProjects that fetch token and project metadata from external endpoints (e.g., https://emblemvault.dev/api/migrate-fun/).
  • Boundary markers: The provided code examples do not implement explicit data sanitization or boundary markers for the fetched JSON content, though the documentation contains warnings to treat metadata as display-only.
  • Capability inventory: The skill focuses on React frontend integration; the generated code does not include server-side execution, file writes, or shell access. However, the data is processed within the agent's context during development.
  • Sanitization: No specific sanitization logic is provided in the hook implementations shown.
  • [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install several external dependencies.
  • Evidence: Files references/auth-react.md, references/emblem-ai-react.md, and references/migratefun-react.md instruct the user to install @emblemvault/emblem-auth-react, @emblemvault/hustle-react, and @emblemvault/migratefun-react via the NPM registry.
  • Context: These packages are first-party libraries maintained by the vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:36 PM
Security Audit — agent-trust-hub — emblem-ai-react