emblem-ai-react
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from remote APIs to populate React UI components.
- Ingestion points: File
references/migratefun-react.mddescribes hooks such asuseProjectanduseProjectsthat fetch token and project metadata from external endpoints (e.g.,https://emblemvault.dev/api/migrate-fun/). - Boundary markers: The provided code examples do not implement explicit data sanitization or boundary markers for the fetched JSON content, though the documentation contains warnings to treat metadata as display-only.
- Capability inventory: The skill focuses on React frontend integration; the generated code does not include server-side execution, file writes, or shell access. However, the data is processed within the agent's context during development.
- Sanitization: No specific sanitization logic is provided in the hook implementations shown.
- [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install several external dependencies.
- Evidence: Files
references/auth-react.md,references/emblem-ai-react.md, andreferences/migratefun-react.mdinstruct the user to install@emblemvault/emblem-auth-react,@emblemvault/hustle-react, and@emblemvault/migratefun-reactvia the NPM registry. - Context: These packages are first-party libraries maintained by the vendor.
Audit Metadata