skills/poletron/custom-rules/react-19/Gen Agent Trust Hub

react-19

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): The skill contains no attempts to override agent behavior, bypass safety filters, or extract system prompts. All instructions are focused on React 19 development practices.- [Data Exposure & Exfiltration] (SAFE): No sensitive file paths, hardcoded credentials, or network exfiltration patterns were detected. The use of WebFetch/WebSearch is listed as an allowed tool but not used for exfiltration within the provided logic.- [Obfuscation] (SAFE): No Base64, zero-width characters, homoglyphs, or encoded commands were found. The code and markdown are clear and human-readable.- [Unverifiable Dependencies & Remote Code Execution] (SAFE): No external script downloads or package installations (e.g., npm install, pip install) are performed by the skill.- [Privilege Escalation & Persistence] (SAFE): No commands involving sudo, chmod, or modification of system startup files/crontabs were found.- [Indirect Prompt Injection] (SAFE): While the skill interacts with .tsx files, it does not interpolate untrusted external data into prompts in a way that suggests a vulnerability to indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:31 PM