clerk-react-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled data from an authentication provider, which constitutes an indirect injection surface.
- Ingestion points: User profile data is accessed through the
useUseranduseAuthhooks and displayed in UI components as seen inreferences/hooks.md. - Boundary markers: No specific delimiters or boundary warnings are implemented for external user data.
- Capability inventory: The skill includes patterns for making authorized API requests using
fetchwith session tokens inreferences/hooks.md. - Sanitization: Standard React JSX interpolation is used, which provides basic protection against XSS but no specific sanitization for indirect prompt injection.
Audit Metadata