react-expert

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow includes the command tsc --noEmit to perform static type checking on implemented components. This is a best-practice validation step in TypeScript development and does not represent a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied React source code and requirements to generate, optimize, or debug features. While the agent has the capability to execute validation commands, the attack surface is typical for coding assistants.
  • Ingestion points: User-provided .tsx and .jsx source files.
  • Boundary markers: None defined in the skill instructions.
  • Capability inventory: Shell execution of validation tools (tsc) and test runners.
  • Sanitization: None specified within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:52 PM
Security Audit — agent-trust-hub — react-expert