web-state-jotai

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a reference for implementing Jotai in web applications. The code snippets follow standard React and Jotai best practices, such as defining atoms at the module level to maintain identity stability and using Suspense boundaries for asynchronous operations.
  • [DATA_EXFILTRATION]: While the skill mentions the fetch API for data retrieval in asynchronous atoms, these are generic documentation examples (e.g., /api/users/) and do not point to suspicious or attacker-controlled domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for ingesting external data through network requests. Although this creates a theoretical surface for indirect injection if an application processes malicious API responses, the skill itself is purely instructional and does not exhibit malicious behavior or lack reasonable boundaries for its context as a development guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:57 PM
Security Audit — agent-trust-hub — web-state-jotai