remix-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill promotes secure development practices, including server-side validation with Zod and proper cookie security settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for handling user data through loaders and actions, which represents a standard attack surface for web applications. The skill mitigates this by explicitly recommending input validation and HTML sanitization.
  • Ingestion points: User input is ingested via request.formData() and request.json() in multiple examples within references/EXAMPLES.md.
  • Boundary markers: The skill instructs the use of Zod for schema validation but does not explicitly use delimiters for untrusted data in the prompt structure.
  • Capability inventory: The skill utilizes Bash, Write, Edit, and Read tools as defined in the allowed-tools metadata.
  • Sanitization: The best practices section in SKILL.md explicitly mandates that users 'Validate all user input' and 'Sanitize HTML content'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — remix-expert