use-dom
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a bridge between a webview and native code. Ingestion points include serializable props passed to DOM components in 'SKILL.md'. Capability inventory includes exposed native functions like 'Alert.alert' and 'saveData'. While the documentation acknowledges the surface and suggests user review in the limitations section, it represents a standard feature rather than an exploit.
- [EXTERNAL_DOWNLOADS]: The skill references dependencies on well-known libraries including 'recharts', 'react-syntax-highlighter', and 'expo-router'. These are standard packages from trusted or well-known sources and are used appropriately within the technical documentation.
Audit Metadata