react-doctor

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a local-triage playbook and rule-specific recipes from the react.doctor domain. These resources are used to guide the agent through the diagnostic and repair process at runtime.\n- [PROMPT_INJECTION]: The skill contains instructions to fetch the canonical local-triage playbook and follow every step in it. This constitutes an indirect prompt injection surface where external content can dictate agent behavior.\n
  • Ingestion points: SKILL.md fetches content via curl from react.doctor.\n
  • Boundary markers: Absent; the remote playbook is designated as the single source of truth.\n
  • Capability inventory: The agent can execute npx commands and modify files in the working tree.\n
  • Sanitization: No validation or sanitization of the remote markdown content is performed before the agent follows its instructions.\n- [COMMAND_EXECUTION]: The skill uses npx react-doctor@latest to perform code scans and configuration updates. This command downloads and executes the package from the NPM registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — react-doctor