react-hook-creator
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill identifies a potential vulnerability surface when processing untrusted code files. \n- Ingestion points: Access to the
Readtool to ingest frontend source files. \n- Boundary markers: Absent; no instructions define how to distinguish between code to be analyzed and potential embedded instructions. \n- Capability inventory: Toolset includesBash,Write,Edit, andGrep. \n- Sanitization: Absent; no logic provided to sanitize or escape data before processing or generation.\n- [No Code Detected] (SAFE): The skill consists only of a metadata file (SKILL.md) and does not include any executable scripts or binary files, minimizing the direct risk of malware or remote code execution.
Audit Metadata