storybook-testing

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMMETADATA_POISONINGREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill uses 'future-faked' versioning and dates, claiming compatibility with non-existent versions of software such as Storybook 10, Vite 8, and Claude Code 2.1.251, with a reference date in April 2026. This deceptive metadata could cause an agent to attempt to follow invalid patterns or install non-existent versions of packages.- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to install and execute unverified software packages, specifically mcp-add and @storybook/addon-mcp. These packages are not standard components of the current Storybook ecosystem and their execution via npx poses a risk of remote code execution if the packages are malicious or have been registered by an attacker under those names.- [INDIRECT_PROMPT_INJECTION]: The skill describes an automated testing and 'self-heal' loop where the agent processes the output of component tests. This creates an indirect prompt injection surface where a component containing malicious instructions could influence the agent's behavior when it reads the test failure reports.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 05:22 AM
Security Audit — agent-trust-hub — storybook-testing