storybook-testing
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMMETADATA_POISONINGREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill uses 'future-faked' versioning and dates, claiming compatibility with non-existent versions of software such as Storybook 10, Vite 8, and Claude Code 2.1.251, with a reference date in April 2026. This deceptive metadata could cause an agent to attempt to follow invalid patterns or install non-existent versions of packages.- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to install and execute unverified software packages, specifically
mcp-addand@storybook/addon-mcp. These packages are not standard components of the current Storybook ecosystem and their execution vianpxposes a risk of remote code execution if the packages are malicious or have been registered by an attacker under those names.- [INDIRECT_PROMPT_INJECTION]: The skill describes an automated testing and 'self-heal' loop where the agent processes the output of component tests. This creates an indirect prompt injection surface where a component containing malicious instructions could influence the agent's behavior when it reads the test failure reports.
Audit Metadata