reactlynx-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted ReactLynx source code provided by users.
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to userg(ripgrep) and a Node.js-based scanner to read file contents from the repository into the agent's context. - Boundary markers: The instructions do not specify any delimiters or directives to prevent the agent from following instructions embedded within the source code being analyzed.
- Capability inventory: The agent can execute shell commands (
node,rg) and perform file system modifications during the refactoring process. - Sanitization: The input code is parsed by a local script using regex, but the agent reads the raw file content without sanitization.
- [DYNAMIC_EXECUTION]: The
SKILL.mdfile instructs the agent to execute a bundled JavaScript scanner (scripts/index.mjs) using thenode -ecommand to perform code analysis. - [COMMAND_EXECUTION]: The workflow relies on shell commands such as
rgfor file searching andnodefor running the logic in the skill's utility scripts.
Audit Metadata