reka-ui
Fail
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's component documentation (found in
components/*.md) is generated by fetching metadata from an external repository on GitHub (github.com/unovue/reka-ui). This creates a vulnerability surface where a compromise of the remote repository could result in malicious instructions being embedded in the skill's reference files. - Ingestion points: The
scripts/generate-components.tsscript fetches content fromraw.githubusercontent.com/unovue/reka-ui/main/docs/content/meta/. - Boundary markers: Absent. The resulting documentation files contain raw component properties and descriptions without clear delimiters to prevent the agent from following instructions potentially embedded in that data.
- Capability inventory: The skill primarily provides context for Vue component development. The generation script itself possesses
fetchandfs.writeFileSynccapabilities. - Sanitization: The script uses
JSON.parseon data extracted via regex but does not specifically filter or sanitize the content for AI instructions before writing to the local filesystem. - [EXTERNAL_DOWNLOADS]: The maintenance script
scripts/generate-components.tsdownloads component definitions from GitHub. This targets a well-known service and the official source for the library described by the skill. - [DYNAMIC_EXECUTION]: The skill includes a TypeScript utility (
scripts/generate-components.ts) designed to be executed viatsx. This script performs network operations to download external content and modifies the local file structure of the skill by writing documentation files.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata