react-artifacts
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve executing local shell scripts (
scripts/init-artifact.shandscripts/bundle-artifact.sh) to initialize projects and bundle assets into single HTML files. These are typical automation tasks for a development environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process React component code to build artifacts, which represents an indirect injection surface. Mandatory Evidence Chain: 1. Ingestion points: React component files (.tsx) provided by the user or external sources. 2. Boundary markers: Not explicitly defined in instructions. 3. Capability inventory: Shell script execution (SKILL.md). 4. Sanitization: Not specified. The risk is minimized as this is the primary intended functionality of the skill.
Audit Metadata