react-doctor
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a local-triage playbook and rule-specific recipes from the react.doctor domain. These resources are used to guide the agent through the diagnostic and repair process at runtime.\n- [PROMPT_INJECTION]: The skill contains instructions to fetch the canonical local-triage playbook and follow every step in it. This constitutes an indirect prompt injection surface where external content can dictate agent behavior.\n
- Ingestion points: SKILL.md fetches content via curl from react.doctor.\n
- Boundary markers: Absent; the remote playbook is designated as the single source of truth.\n
- Capability inventory: The agent can execute npx commands and modify files in the working tree.\n
- Sanitization: No validation or sanitization of the remote markdown content is performed before the agent follows its instructions.\n- [COMMAND_EXECUTION]: The skill uses npx react-doctor@latest to perform code scans and configuration updates. This command downloads and executes the package from the NPM registry.
Audit Metadata