skills/pedronauck/skills/xstate/Gen Agent Trust Hub

xstate

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based, providing code snippets and guidelines for using XState v5. All code examples follow industry best practices for state management and data fetching.
  • [PROMPT_INJECTION]: No prompt injection patterns, override instructions, or jailbreak attempts were detected in the instructions or metadata.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were found. API calls in code snippets use relative paths (e.g., /api/users/) which is standard for web development documentation.
  • [OBFUSCATION]: No obfuscated content, Base64-encoded commands, zero-width characters, or homoglyph attacks were identified.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform or instruct the agent to perform any remote code execution. It references standard, well-known packages from official registries.
  • [DYNAMIC_CONTEXT_INJECTION]: No instances of dynamic context execution using the !command syntax were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a reference for code generation and analysis. While it processes data (XState logic), it does not exhibit vulnerability to indirect injection as it focuses on developer guidance and static code patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:30 AM
Security Audit — agent-trust-hub — xstate