ahooks
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill defines patterns for using
useLocalStorageStatewhich reads data from the browser'slocalStorage. While this is an ingestion point for potentially untrusted data (if modified by a user or another script), the risk is minimal as the skill only influences local UI state and specifically warns against storing sensitive data. - [SAFE] (SAFE): No other threat patterns such as prompt injection, data exfiltration, or remote code execution were identified in the instructions or code examples.
Audit Metadata