react-doctor
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
react-doctortool viapnpm execto perform repository scans, explain diagnostic rules, and modify project configuration files (e.g.,doctor.config.ts).- [DATA_EXFILTRATION]: Thereact-doctorutility includes built-in telemetry, crash reporting, and a remote scoring service that sends data toreact.doctorby default. The skill documents the usage of the--no-scoreflag to opt-out of these network activities.- [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by processing outputs from thereact-doctorCLI and findings from the user's React source code. Ingestion points include CLI command output and diagnostic findings from code files. No explicit boundary markers or sanitization logic are defined in the instructions to separate untrusted data from the agent's context. The skill maintains shell command execution capabilities viapnpm exec.- [EXTERNAL_DOWNLOADS]: The skill references external rule documentation and recipes hosted athttps://www.react.doctorand assumes the availability of thereact-doctorpackage.
Audit Metadata