react-component-diagnosis

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override system constraints was found. The skill includes triggers for relevant user requests but does not attempt to subvert the agent's core behavior.
  • [DATA_EXFILTRATION]: No network operations or commands to transmit data externally were detected. The skill's primary function is reading local source files for analysis purposes.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or instructions to access sensitive credential files (like .env or .ssh) were found.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote script downloads or installations of untrusted packages. It contains no commands that execute code from the internet.
  • [COMMAND_EXECUTION]: There are no shell commands or subprocess calls that could be used for malicious purposes. The skill focuses entirely on code analysis and reporting.
  • [OBFUSCATION]: The instructions are clear and transparent. No hidden characters, encoded strings, or misleading metadata techniques were identified.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (React source code), it lacks the dangerous capabilities (like network access or shell execution) required for an attacker to exploit this surface. It is used as a diagnostic tool rather than an execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:50 AM
Security Audit — agent-trust-hub — react-component-diagnosis