react
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified in the skill's instructions or code examples. The logic is focused entirely on React 19 best practices.\n- [INDIRECT_PROMPT_INJECTION]: The skill audits and refactors untrusted user-provided React source code. This creates a vulnerability surface for indirect prompt injection, where malicious instructions hidden in the code being analyzed could attempt to override the agent's behavior. The skill includes a detailed review algorithm to help guide the agent through a structured process, which provides some defensive structure.\n- [EXTERNAL_DOWNLOADS]: The skill links to official React documentation and GitHub repositories owned by Facebook/Meta. These references to trusted organizations are safe and do not contribute to security risks.
Audit Metadata