react
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): The skill provides documentation and code snippets for React functional components, custom hooks, and state management. No malicious patterns, obfuscation, or data exfiltration attempts were detected.
- [Indirect Prompt Injection] (SAFE): The skill defines a surface for processing untrusted data by allowing tools to read and grep project files, which is necessary for its purpose as a development tool.
- Ingestion points: The skill uses
Read,Glob, andGreptools to ingest content from the project directory. - Boundary markers: None are defined in the skill instructions to separate code from instructions.
- Capability inventory: The skill allows
Bash,Write, andEdittools, which could be used to execute commands or modify files if the agent were manipulated. - Sanitization: No sanitization logic is provided within the skill itself, relying on the agent's core safety layers.
Audit Metadata