web-state-pinia

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of Markdown-based guidelines for Vue and Pinia state management. It contains no executable scripts, shell commands, or network exfiltration logic.
  • [DATA_EXPOSURE]: The skill provides defensive programming advice, warning developers against persisting tokens, credentials, or personal data in web storage (localStorage/sessionStorage) due to risks of script access by other scripts on the page.
  • [INDIRECT_PROMPT_INJECTION]: The skill highlights security considerations for Server-Side Rendering (SSR). It recommends using the @nuxt/devalue library for state serialization to ensure that user-controlled data cannot escape injected script tags, effectively mitigating potential injection or XSS vectors in the rendered page.
  • [EXTERNAL_DOWNLOADS]: The metadata.yaml file references a schema from the official repository of the vendor agents-inc. This is a standard configuration reference and does not involve the execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:57 PM
Security Audit — agent-trust-hub — web-state-pinia