tedi-react

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands for environment inspection, including npm ls to verify package versions and grep to search lockfiles for specific dependency resolutions.
  • [DYNAMIC_EXECUTION]: Python one-liners (python3 -c) are used to parse and extract information from the library's component.manifest.json file. These scripts are hardcoded templates designed for metadata processing of local project files.
  • [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read content from various local project files (manifests, TypeScript declaration files, and lockfiles) and remote source code from GitHub. This creates an attack surface where content within these files could potentially influence agent behavior.
  • Ingestion points: component.manifest.json, index.d.ts, package-lock.json, and raw source code from the project's GitHub repository.
  • Boundary markers: The instructions do not define specific delimiters for separating data from instructions when reading these files.
  • Capability inventory: The skill uses file system read access, shell command execution (npm, grep), and Python script execution.
  • Sanitization: Information from the manifest is processed using the standard Python json library, providing basic protection against malformed data.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation and source code from the official GitHub repository and Storybook instance of the vendor. These are legitimate resources associated with the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:03 AM
Security Audit — agent-trust-hub — tedi-react