react-code-smells

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOW
Full Analysis
  • [SAFE] (SAFE): The skill consists entirely of markdown documentation and educational code examples for React. No malicious logic, prompt injections, or unauthorized data access patterns were detected.\n- [COMMAND_EXECUTION] (LOW): Several reference files mention standard development commands such as 'npx madge' and 'npm install'. These are presented as manual tools for developers to improve code quality and are not configured for automated or hidden execution by the agent.\n- [EXTERNAL_DOWNLOADS] (INFO): The documentation references standard, trusted React libraries like 'react', 'nanoid', 'msw', and 'use-context-selector'. These are well-established community tools and do not involve untrusted or suspicious download sources.\n- [DATA_EXFILTRATION] (SAFE): Code snippets illustrate data fetching and WebSocket patterns using 'fetch' and 'WebSocket'. These are purely illustrative of React's synchronization patterns and do not contain logic for exfiltrating sensitive data or credentials.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:04 PM