react-hook-form

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides detailed instructions for ingesting and managing untrusted data via React Hook Form inputs.\n
  • Ingestion points: User-controlled data enters the agent context through form fields managed by useForm, register, useWatch, and Controller components, as documented in SKILL.md and AGENTS.md.\n
  • Boundary markers: The skill explicitly advocates for the use of validation resolvers (e.g., Zod, Yup) in references/valid-inline-vs-resolver.md and references/valid-resolver-caching.md to establish structural and content boundaries for processed data.\n
  • Capability inventory: While the skill itself is instructional markdown and does not execute code, the implementation of its rules involves handling potentially malicious input strings that could influence downstream agent actions or application state.\n
  • Sanitization: The skill prioritizes input sanitization and type coercion through strict schema validation and transformation rules (e.g., references/integ-value-transform.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — react-hook-form