rivetkit-client-react

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a documentation resource for the @rivetkit/react library. It contains code snippets and architectural guidance consistent with standard frontend development practices.
  • [EXTERNAL_DOWNLOADS]: The skill references the official @rivetkit/react package on npm and suggests adding the rivet-dev/skills extension. These are well-known development resources within the Rivet ecosystem.
  • [COMMAND_EXECUTION]: Provides example shell commands for installing dependencies and adding related skills (e.g., npm install, npx skills add). These are presented as instructional steps for the user.
  • [PROMPT_INJECTION]: The skill includes proactive security documentation, specifically warning developers to use arrays for keys instead of string interpolation to prevent key injection attacks from untrusted user input.
  • [CREDENTIALS_UNSAFE]: While the skill discusses authentication tokens (RIVET_TOKEN) and URL-based authentication syntax, it uses clear placeholders like pk_... and environment variable names rather than exposing actual secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — rivetkit-client-react