react-flow
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides expert-level documentation and best practices for the
@xyflow/reactlibrary. The instructions inSKILL.mdare focused on ensuring the AI generates functional, performant, and correctly styled React code, such as requiring explicit container dimensions and promoting state immutability. - [SAFE]: All external libraries mentioned in the reference files (e.g.,
zustand,dagre,elkjs,d3-force) are well-known, industry-standard packages used for state management and graph layout. No suspicious or unverified dependencies were identified. - [SAFE]: There are no indicators of prompt injection, data exfiltration, or persistence mechanisms. The skill does not attempt to access sensitive local files or perform unauthorized network requests.
- [SAFE]: The use of
npx skills addin the documentation is the standard installation method for the platform and is consistent with the vendor's context.
Audit Metadata