storybook-pentest

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions involve running shell commands via npx for standard testing utilities, including vitest and test-storybook. These tools are used within their intended purpose of project testing and verification.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources, documentation, and tools from established and well-known organizations such as Google, Microsoft, Netflix, W3C, and open-source projects like Storybook and Deque.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and analyze external Storybook manifests and component source code.
  • Ingestion points: Storybook index.json (references/surface/story-index.md) and component props documentation (references/surface/mcp.md).
  • Boundary markers: None explicitly defined to isolate ingested data from agent instructions.
  • Capability inventory: Shell access via npx commands and browser automation via Playwright.
  • Sanitization: Not specified for the ingested component content.
  • [SAFE]: No malicious patterns, obfuscation, Base64-encoded payloads, or persistence mechanisms were detected. The skill provides a structured methodology for auditing user interfaces using legitimate developer tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 08:50 AM
Security Audit — agent-trust-hub — storybook-pentest