react-change-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reviews code diffs and repository content, which are untrusted ingestion points for malicious instructions.\n
  • Ingestion points: Git diffs and local repository files as described in SKILL.md.\n
  • Boundary markers: Instructions do not provide delimiters or warnings to ignore code-embedded instructions.\n
  • Capability inventory: Authorization to run repository-defined diagnostic commands and perform code inspection.\n
  • Sanitization: None provided.\n- [COMMAND_EXECUTION]: The skill instructions allow the agent to run commands found within the target repository, which could be malicious.\n
  • Evidence: Guidance in references/review-checks.md to 'Use the repository's existing diagnostic command if available'.\n- [EXTERNAL_DOWNLOADS]: The skill loads architectural patterns and guidance from Vercel.\n
  • Evidence: References to 'vercel-composition-patterns' and 'vercel-react-best-practices' in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:08 PM
Security Audit — agent-trust-hub — react-change-review