base-ui-react

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill includes unverifiable and potentially misleading claims regarding its efficiency and safety, such as "Error Prevention: 100%" and "Token Savings: ~62%." These metrics could lead users to over-rely on the skill's automated migration and template components without proper oversight.\n- [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by processing external code files during migration tasks.\n
  • Ingestion points: The skill is designed to process user-provided React component source code (e.g., Radix UI component files like Dialog.tsx) via a migration script.\n
  • Boundary markers: There are no explicit instructions or delimiters mentioned to prevent the agent from following instructions that might be embedded as comments or metadata within the code being migrated.\n
  • Capability inventory: The skill references shell scripts (migrate-radix-component.sh) that perform file modifications and utilizes package installation commands.\n
  • Sanitization: No process for sanitizing or validating the input code before modification is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:11 PM
Security Audit — agent-trust-hub — base-ui-react