specsfy-specialist-react

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions strictly focus on React development workflows and do not contain any patterns intended to bypass safety filters, override system instructions, or extract system prompts.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation from trusted sources including react.dev, testing-library.com, and w3.org. No scripts or binary dependencies are downloaded or executed.
  • [DATA_EXFILTRATION]: There are no commands or instructions involving network requests to untrusted domains or access to sensitive local files (e.g., credentials, environment variables).
  • [COMMAND_EXECUTION]: The skill consists entirely of markdown-based documentation and instructions. It does not include shell commands, script execution, or requests for administrative privileges.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process React development tasks, it lacks the dangerous capabilities (like file writing or network operations) that would make it vulnerable to exploitation via untrusted data. It provides guidance rather than autonomous execution.
  • [OBFUSCATION]: Analysis of the markdown and YAML files revealed no hidden content, base64 encoding, zero-width characters, or homoglyph attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 12:55 PM
Security Audit — agent-trust-hub — specsfy-specialist-react