component-extraction-judgment
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted frontend source code (JSX, Vue, Svelte) which could contain embedded instructions. 1. Ingestion points: Source code files processed during the refactoring workflow. 2. Boundary markers: The skill uses an 'Evidence Tier' classification system (T1-T4) to structure decision-making. 3. Capability inventory: Suggested execution of scanners like react-unify and duplicalis. 4. Sanitization: Relies on human-in-the-loop verification and explicit evidence gathering rather than automated filtering.
- [COMMAND_EXECUTION]: The skill mentions running command-line utilities (
react-unify scan,duplicalis scan). Although it includes safety instructions such as using read-only mode and not adding new dependencies, these tools represent a command execution capability. - [EXTERNAL_DOWNLOADS]: The skill references multiple external GitHub repositories in its prior art documentation that are not from trusted organizations. These include niche tools for component scanning and design auditing (e.g., from developers Muronuch, pfrankov, and gbechtold) which could represent unverified code if accessed by the agent.
Audit Metadata