react-refactor

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides educational content focused on React architecture, such as component decomposition and hook patterns. All code examples use standard React and TypeScript syntax without any dangerous operations.
  • [INDIRECT_PROMPT_INJECTION]: As a refactoring guide, the skill creates an ingestion surface where an agent processes user-provided React codebases. 1. Ingestion points: Agent reads and refactors user source code (references/*.md). 2. Boundary markers: Absent; no specific instructions are provided to the agent for isolating or ignoring adversarial strings embedded in target code. 3. Capability inventory: The agent typically has file-write and test execution permissions. 4. Sanitization: No sanitization methods for input code are described. This is a standard risk for analysis-oriented skills.
  • [EXTERNAL_DOWNLOADS]: The documentation references established industry libraries including @tanstack/react-query, react-error-boundary, msw, and vitest. All external links point to reputable domains such as react.dev, kentcdodds.com, and patterns.dev.
  • [COMMAND_EXECUTION]: The README mentions standard package management and validation commands (pnpm install, pnpm build, pnpm validate) for contributors, which are standard in JS/TS development environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:52 PM
Security Audit — agent-trust-hub — react-refactor