react
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes
scripts/verify.shwhich executes project-local build and linting tools. - Evidence: The script attempts to run
eslint,tsc,vitest, andviteusing local package managers (pnpm,yarn,npm). - Security Note: The script uses
npx --no-installwhere applicable, which is a security best practice to prevent the execution of unvetted packages from the registry. - The final build step writes output to the local
dist/directory. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process local project files (e.g.,
package.jsonand React source code) to provide architectural advice, creating an ingestion surface for untrusted content. - Ingestion points:
SKILL.mdinstructs the agent to readpackage.jsonand component code to determine the appropriate framework and state management patterns. - Boundary markers: The skill uses specific logic tables to route advice based on detected dependencies, providing a degree of logical isolation.
- Capability inventory: The skill can execute local build scripts via
scripts/verify.shbut does not perform network operations or access sensitive system files. - Sanitization: No explicit sanitization of file content is performed prior to processing.
- [DATA_EXPOSURE]: The skill includes proactive security guidance regarding environment variables.
- Evidence:
SKILL.mdexplicitly warns users thatVITE_-prefixed variables are public in the browser bundle and warns against storing secrets likeVITE_API_SECRET.
Audit Metadata