remix-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill promotes secure development practices, including server-side validation with Zod and proper cookie security settings.
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for handling user data through loaders and actions, which represents a standard attack surface for web applications. The skill mitigates this by explicitly recommending input validation and HTML sanitization.
- Ingestion points: User input is ingested via
request.formData()andrequest.json()in multiple examples withinreferences/EXAMPLES.md. - Boundary markers: The skill instructs the use of Zod for schema validation but does not explicitly use delimiters for untrusted data in the prompt structure.
- Capability inventory: The skill utilizes
Bash,Write,Edit, andReadtools as defined in theallowed-toolsmetadata. - Sanitization: The best practices section in
SKILL.mdexplicitly mandates that users 'Validate all user input' and 'Sanitize HTML content'.
Audit Metadata