storybook-stories
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to analyze local component source code to produce Storybook documentation, which creates a surface for indirect prompt injection if the source code contains malicious instructions.\n
- Ingestion points: Local application source code files (e.g.,
src/components/base/accordion.tsx) are read by the agent to understand component structure.\n - Boundary markers: No specific delimiters or instructions to ignore embedded instructions are defined for the source code ingestion process.\n
- Capability inventory: The skill requires the agent to generate and write new React/TypeScript files (
.stories.tsx) to the project directory.\n - Sanitization: No sanitization or validation logic is specified for the inputs derived from existing source files.
Audit Metadata