react-expert

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The author URL in the YAML frontmatter (https://github.com/Jeffallan) does not match the provided author information (wesleyegberto), which constitutes a metadata discrepancy.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze user-provided requirements and code snippets to drive implementation. It lacks instructions to ignore or sanitize embedded instructions within this data, exposing a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (Core Workflow)
  • Boundary markers: Absent
  • Capability inventory: The skill guides the agent in generating React code and application structures
  • Sanitization: Absent
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 06:52 AM
Security Audit — agent-trust-hub — react-expert