sb-flows

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, data exfiltration, or obfuscation techniques were detected. The skill operates locally on the project's source code to generate JSON artifacts and Storybook wrappers.
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts (extract-flows.sh, scaffold-wrapper.sh) and a Node.js template (extract-app-graph.mjs) to perform discovery of routes and navigation edges. These actions are performed using universal primitives (Bash, Grep, etc.) and are consistent with the skill's primary purpose of application auditing.
  • [PROMPT_INJECTION]: The instructions provided to the agent focus on maintaining data integrity and technical accuracy, such as the directive to validate edges and avoid hallucinating empty nodes. No attempts to bypass safety filters or override system instructions were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:17 PM
Security Audit — agent-trust-hub — sb-flows