react-markdown

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches content from official GitHub repositories for remarkjs and rehypejs using WebFetch to provide current API details.
  • Ingestion points: SKILL.md (via WebFetch calls).
  • Boundary markers: Absent.
  • Capability inventory: No command execution, file system writes, or sensitive network operations are defined in the skill.
  • Sanitization: Absent.
  • [PROMPT_INJECTION]: Uses strong instructional language to ensure the agent prioritizes live documentation over potentially outdated training data. These instructions are focused on accuracy and do not attempt to bypass safety constraints.
  • [COMMAND_EXECUTION]: Provides standard instructions for installing legitimate NPM packages (react-markdown, remark-gfm, rehype-highlight) using common package managers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 01:39 AM
Security Audit — agent-trust-hub — react-markdown