web-state-pinia
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of Markdown-based guidelines for Vue and Pinia state management. It contains no executable scripts, shell commands, or network exfiltration logic.
- [DATA_EXPOSURE]: The skill provides defensive programming advice, warning developers against persisting tokens, credentials, or personal data in web storage (localStorage/sessionStorage) due to risks of script access by other scripts on the page.
- [INDIRECT_PROMPT_INJECTION]: The skill highlights security considerations for Server-Side Rendering (SSR). It recommends using the
@nuxt/devaluelibrary for state serialization to ensure that user-controlled data cannot escape injected script tags, effectively mitigating potential injection or XSS vectors in the rendered page. - [EXTERNAL_DOWNLOADS]: The
metadata.yamlfile references a schema from the official repository of the vendoragents-inc. This is a standard configuration reference and does not involve the execution of remote code.
Audit Metadata