component-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a set of development standards for React components, emphasizing the use of semantic HTML, ARIA roles, and the Slot pattern for composition. It references established open-source libraries such as Radix UI and Tailwind CSS.
- [INDIRECT_PROMPT_INJECTION]: The skill includes a command (
/component-review) that processes external source code, which serves as an ingestion point for untrusted data. - Ingestion points: Source code files provided by the user for review as defined in
SKILL.md. - Boundary markers: The workflow instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded within the reviewed code.
- Capability inventory: The skill's functionality is restricted to textual analysis and code generation. It does not contain instructions for subprocess execution, network exfiltration, or persistence mechanisms.
- Sanitization: No specific sanitization or filtering of input content is mandated in the provided documentation.
Audit Metadata