react-expert

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a link to an external documentation resource (jeffallan.github.io/claude-skills/skills/frontend/react-expert/) that is blacklisted by automated security scanners. This poses a risk as the site may host malicious content or serve as a vector for secondary attacks.\n- [METADATA_POISONING]: The main skill instruction file (SKILL.md) has been flagged with a malicious reputation (FileRepMalware) by security scanners. This indicates that the file content or its origin is considered untrustworthy or potentially harmful.\n- [COMMAND_EXECUTION]: The skill instructs the agent to run the 'tsc --noEmit' command in the local terminal. While this is a standard TypeScript validation step, providing such instructions within a file of malicious reputation increases the risk of the agent performing unauthorized actions or being used as a staging point for broader command execution attacks.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 08:08 AM
Security Audit — agent-trust-hub — react-expert