valtio
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- SAFE (SAFE): No security issues were detected across any of the analyzed threat categories.
- Data Exposure & Exfiltration (SAFE): The documentation includes patterns for state persistence using
localStorage. This is an intended feature of the library and is implemented using standardJSON.stringifyandJSON.parsemethods. No evidence of data exfiltration to unauthorized external servers was found. - Prompt Injection (SAFE): The content consists purely of instructional documentation and code examples for a technical library. There are no attempts to override agent instructions or bypass safety guardrails.
- Remote Code Execution (SAFE): No scripts or commands that download and execute remote code were found. The skill relies entirely on static markdown content.
- Persistence Mechanisms (SAFE): While the skill discusses state persistence, it refers to legitimate web application state persistence in the browser's
localStorageand does not attempt to establish unauthorized persistence on a host system.
Audit Metadata