react-expert
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow includes the command
tsc --noEmitto perform static type checking on implemented components. This is a best-practice validation step in TypeScript development and does not represent a security risk. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied React source code and requirements to generate, optimize, or debug features. While the agent has the capability to execute validation commands, the attack surface is typical for coding assistants.
- Ingestion points: User-provided .tsx and .jsx source files.
- Boundary markers: None defined in the skill instructions.
- Capability inventory: Shell execution of validation tools (
tsc) and test runners. - Sanitization: None specified within the skill instructions.
Audit Metadata