react
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-provided source code which represents an indirect prompt injection surface where malicious instructions could be embedded in data.
- Ingestion points: User React application source code and configuration files.
- Boundary markers: The workflow does not explicitly define delimiters for untrusted user code.
- Capability inventory: The skill utilizes
npmfor building, testing, and linting, andrgfor file searching. - Sanitization: No specific sanitization or escaping of user-provided code is mentioned before processing.
- [COMMAND_EXECUTION]: Includes instructions for running standard lifecycle scripts such as
npm run build,npm run test, andnpm run lintwithin the development environment. - [EXTERNAL_DOWNLOADS]: References and recommends the integration of various well-known third-party libraries and frameworks from trusted ecosystems, including Meta, Microsoft, and the TanStack community.
Audit Metadata