skills/ericrisco/rsc-harness/react/Gen Agent Trust Hub

react

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes scripts/verify.sh which executes project-local build and linting tools.
  • Evidence: The script attempts to run eslint, tsc, vitest, and vite using local package managers (pnpm, yarn, npm).
  • Security Note: The script uses npx --no-install where applicable, which is a security best practice to prevent the execution of unvetted packages from the registry.
  • The final build step writes output to the local dist/ directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process local project files (e.g., package.json and React source code) to provide architectural advice, creating an ingestion surface for untrusted content.
  • Ingestion points: SKILL.md instructs the agent to read package.json and component code to determine the appropriate framework and state management patterns.
  • Boundary markers: The skill uses specific logic tables to route advice based on detected dependencies, providing a degree of logical isolation.
  • Capability inventory: The skill can execute local build scripts via scripts/verify.sh but does not perform network operations or access sensitive system files.
  • Sanitization: No explicit sanitization of file content is performed prior to processing.
  • [DATA_EXPOSURE]: The skill includes proactive security guidance regarding environment variables.
  • Evidence: SKILL.md explicitly warns users that VITE_-prefixed variables are public in the browser bundle and warns against storing secrets like VITE_API_SECRET.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:54 PM
Security Audit — agent-trust-hub — react