storybook-pentest
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve running shell commands via
npxfor standard testing utilities, includingvitestandtest-storybook. These tools are used within their intended purpose of project testing and verification. - [EXTERNAL_DOWNLOADS]: The skill references external resources, documentation, and tools from established and well-known organizations such as Google, Microsoft, Netflix, W3C, and open-source projects like Storybook and Deque.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and analyze external Storybook manifests and component source code.
- Ingestion points: Storybook
index.json(references/surface/story-index.md) and component props documentation (references/surface/mcp.md). - Boundary markers: None explicitly defined to isolate ingested data from agent instructions.
- Capability inventory: Shell access via
npxcommands and browser automation via Playwright. - Sanitization: Not specified for the ingested component content.
- [SAFE]: No malicious patterns, obfuscation, Base64-encoded payloads, or persistence mechanisms were detected. The skill provides a structured methodology for auditing user interfaces using legitimate developer tools.
Audit Metadata