frontend-apps
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation recommends the installation of several packages including '@mysten/dapp-kit-react', '@mysten/dapp-kit-core', '@mysten/sui', and '@tanstack/react-query'. These are official packages from the verified vendor (Mysten Labs) or established industry standard libraries for React development.
- [PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sources, specifically the Sui blockchain via the SuiGrpcClient and an external Sui documentation MCP server at 'https://sui.mcp.kapa.ai'. This represents an indirect prompt injection surface inherent to the dApp development use case.
- Ingestion points: On-chain object data, balance information, and AI-generated documentation queries.
- Boundary markers: Not explicitly defined for the external data streams in the provided snippets.
- Capability inventory: Signing and executing transactions, querying balances, and connecting wallets.
- Sanitization: Code examples use structured JSON parsing for blockchain responses to minimize instruction leakage.
- [SAFE]: The 'limitations.md' file provides comprehensive security guidance, explicitly forbidding the storage of mnemonics, private keys, or sensitive backend secrets in the frontend environment, which mitigates major credential exposure risks.
Audit Metadata