react-nextjs-implementation
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to inspect repository conventions and project-specific policy files (e.g., .itsol.md) to inform its actions. If these files are maliciously crafted, they could influence the agent's behavior.
- Ingestion points: Local repository files, including .itsol.md and package configuration files.
- Boundary markers: The skill does not define specific boundaries or ignore-instructions for the data ingested from the project files.
- Capability inventory: The agent is authorized to implement code changes, configure routing, and execute development verification tools.
- Sanitization: No sanitization or validation of the project policy content is specified.
Audit Metadata