xstate
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected in this skill. The content is purely instructional and follows industry-standard practices for the documented libraries.
- [PROMPT_INJECTION]: The instructions do not contain any attempts to override agent behavior, bypass safety guidelines, or extract system prompts.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or suspicious network operations were identified. The API examples use standard REST path placeholders.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of external scripts or binaries.
- [OBFUSCATION]: The skill uses clear TypeScript and JavaScript code snippets with no evidence of Base64 encoding, zero-width characters, or homoglyph-based evasion techniques.
- [PRIVILEGE_ESCALATION]: No commands or instructions relating to elevated permissions or administrative access were found.
- [DYNAMIC_CONTEXT_INJECTION]: No use of shell-execution patterns (such as exclamation mark and backtick syntax) was found in the documentation.
Audit Metadata