preact
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill instructions and documentation prioritize secure development practices, specifically advising on the sanitization of untrusted HTML content via DOMPurify before use with Preact's rendering APIs.
- [EXTERNAL_DOWNLOADS]: The skill utilizes standard, well-known dependencies within the Preact and Vite ecosystems, such as
@preact/signals,preact-router, and@preact/preset-vite. These are official packages sourced from established registries. - [DATA_EXFILTRATION]: No evidence of unauthorized network operations, hardcoded credentials, or sensitive file path access was found in the provided files.
- [PROMPT_INJECTION]: The instructions do not contain attempts to override agent constraints or bypass safety filters. Style directives like 'why use many token when few do trick' are benign stylistic preferences.
- [METADATA_POISONING]: Several reference files (e.g.,
architecture-patterns.md,deployment-pipelines.md) contain large volumes of repetitive, generic technical jargon. This behavior, while unusual, does not contain hidden instructions or malicious payloads and appears to be placeholder content.
Audit Metadata