react-hook-form-audit
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted source code and test files, creating a surface for indirect prompt injection.
- Ingestion points: Local files importing React Hook Form, schemas, and mutation logic (SKILL.md, Step 1).
- Boundary markers: None specified to prevent the agent from following instructions embedded in the code.
- Capability inventory: Execution of shell commands for TypeScript type-checking and running local tests (SKILL.md, Step 4).
- Sanitization: No sanitization or filtering of audited content is mentioned.
- [COMMAND_EXECUTION]: The skill utilizes local development tools by running TypeScript typecheck and focused tests to validate suspected issues (SKILL.md, Step 4).
Audit Metadata