skills/storybookjs/storybook/stories/Gen Agent Trust Hub

stories

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @storybook/addon-mcp package and performs version upgrades for Storybook using npx.
  • [COMMAND_EXECUTION]: Executes shell commands via npx storybook to manage documentation, tool help, and the development server.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches its core development workflow from the output of an external command.
  • Ingestion points: Output of npx storybook skills get stories and command help text.
  • Boundary markers: None; the agent is directed to follow the fetched workflow in its entirety.
  • Capability inventory: File system modifications for UI components and execution of Storybook CLI tools.
  • Sanitization: No validation or sanitization is performed on the fetched workflow before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 03:15 PM
Security Audit — agent-trust-hub — stories