blode-icons-react
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation and workflow guide for a React icon library. All analyzed instructions and references are focused on legitimate development tasks such as installation, API usage, and package release management.
- [EXTERNAL_DOWNLOADS]: The skill references an MCP endpoint (https://blode.co/icons/mcp) and a summary file (https://blode.co/icons/llms.txt). Both reside on the vendor's primary domain (blode.co) and are used to provide the agent with icon metadata and usage examples.
- [COMMAND_EXECUTION]: The skill provides standard development commands (e.g.,
npm install,npm run build,npm run changeset) for the user to execute manually. These are standard procedures for managing a Turborepo monorepo and do not involve silent or malicious execution. - [INDIRECT_PROMPT_INJECTION]: While the skill assists with user-provided icon requests, it serves as a guidance tool rather than an automated execution environment. No vulnerable data ingestion patterns or unsafe command interpolations were identified.
Audit Metadata