react

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided source code which represents an indirect prompt injection surface where malicious instructions could be embedded in data.
  • Ingestion points: User React application source code and configuration files.
  • Boundary markers: The workflow does not explicitly define delimiters for untrusted user code.
  • Capability inventory: The skill utilizes npm for building, testing, and linting, and rg for file searching.
  • Sanitization: No specific sanitization or escaping of user-provided code is mentioned before processing.
  • [COMMAND_EXECUTION]: Includes instructions for running standard lifecycle scripts such as npm run build, npm run test, and npm run lint within the development environment.
  • [EXTERNAL_DOWNLOADS]: References and recommends the integration of various well-known third-party libraries and frameworks from trusted ecosystems, including Meta, Microsoft, and the TanStack community.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — react