rivetkit-client-react
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a documentation resource for the @rivetkit/react library. It contains code snippets and architectural guidance consistent with standard frontend development practices.
- [EXTERNAL_DOWNLOADS]: The skill references the official @rivetkit/react package on npm and suggests adding the rivet-dev/skills extension. These are well-known development resources within the Rivet ecosystem.
- [COMMAND_EXECUTION]: Provides example shell commands for installing dependencies and adding related skills (e.g.,
npm install,npx skills add). These are presented as instructional steps for the user. - [PROMPT_INJECTION]: The skill includes proactive security documentation, specifically warning developers to use arrays for keys instead of string interpolation to prevent key injection attacks from untrusted user input.
- [CREDENTIALS_UNSAFE]: While the skill discusses authentication tokens (
RIVET_TOKEN) and URL-based authentication syntax, it uses clear placeholders likepk_...and environment variable names rather than exposing actual secrets.
Audit Metadata