clerk-react-router-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting untrusted data through
request.formData()in loaders and actions, which is a potential surface for indirect prompt injection if that data is subsequently processed by an AI agent without sanitization. - Ingestion points:
args.request.formData()inSKILL.mdandreferences/loaders-actions.md. - Boundary markers: None identified in the provided patterns; the skill focuses on authentication logic.
- Capability inventory: Includes the
WebFetchtool for remote data operations and standard file system access capabilities. - Sanitization: Not explicitly demonstrated in the authentication-focused code snippets.
Audit Metadata