react-dev
Pass
Audited by Gen Agent Trust Hub on Feb 12, 2026
Risk Level: LOWNO_CODE
Full Analysis
The 'react-dev' skill consists entirely of markdown files and TypeScript code snippets intended for user reference. It explicitly states a 'script-free design' and contains no executable components for the AI agent. All mentions of external dependencies (like npm install react-router or zod) and network operations (fetch calls to example APIs) are part of illustrative code examples for the user, not instructions for the agent to execute. No prompt injection, data exfiltration, obfuscation, privilege escalation, persistence mechanisms, or time-delayed attacks were detected. The skill's content aligns perfectly with its stated purpose of providing React TypeScript knowledge.
Audit Metadata