react-dev

Pass

Audited by Gen Agent Trust Hub on Feb 12, 2026

Risk Level: LOWNO_CODE
Full Analysis

The 'react-dev' skill consists entirely of markdown files and TypeScript code snippets intended for user reference. It explicitly states a 'script-free design' and contains no executable components for the AI agent. All mentions of external dependencies (like npm install react-router or zod) and network operations (fetch calls to example APIs) are part of illustrative code examples for the user, not instructions for the agent to execute. No prompt injection, data exfiltration, obfuscation, privilege escalation, persistence mechanisms, or time-delayed attacks were detected. The skill's content aligns perfectly with its stated purpose of providing React TypeScript knowledge.

Audit Metadata
Risk Level
LOW
Analyzed
Feb 12, 2026, 10:45 PM