toast-notifications

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes message strings that are displayed in the client UI, which presents a surface for indirect injection. 1. Ingestion points: Data enters through the message argument in the setToastCookie function (found in architecture.md). 2. Boundary markers: The skill includes 'Anti-Patterns' and 'Security Considerations' that explicitly warn against including raw user input. 3. Capability inventory: The system renders text content to the user's browser using third-party toast libraries. 4. Sanitization: Documentation advises relying on the library's escaping mechanisms and provides code examples of safe vs. unsafe interpolation.
  • [DATA_EXPOSURE]: The skill implements a cookie-based notification system where the app-toast cookie is configured with httpOnly: false in architecture.md. This is a documented trade-off necessary for the client-side handler to read the message. The risk is mitigated by explicit instructions to never store sensitive data or credentials within the toast payload.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 03:10 PM
Security Audit — agent-trust-hub — toast-notifications