react-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard React architectural patterns and instructions with no evidence of malicious behavior or hidden intent.
  • [EXTERNAL_DOWNLOADS]: Mentions the installation of '@tanstack/react-query', a well-known and reputable library, via standard package managers.
  • [COMMAND_EXECUTION]: References standard project setup commands such as 'npm install' for dependency management, which is expected for the skill's purpose.
  • [DATA_EXFILTRATION]: Code examples use 'fetch' for legitimate API communication within a web application context (/api/users), posing no risk of sensitive data exfiltration from the agent's local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user requirements to generate code (ingestion point). The capability inventory includes standard web tools (npm, fetch, git). Boundary markers and sanitization are not explicitly defined in the skill files, which is consistent with its role as a consultative development specialist.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — react-specialist