hyva-alpine-component

Warn

Audited by Runlayer on Feb 23, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
1
Flagged
1
Chunks
2
Flagged Files (1)
SKILL.mdHIGH
78.3%

Malicious tool definition detected

Tool: SKILL.md [1/2] Description: --- name: hyva-alpine-component description: Write CSP-compatible Alpine.js components for Hyvä themes in Magento 2.

Tool: SKILL.md [2/2] Description: ## Hyva Utility Functions The global `hyva` object provides these utilities: ### Form and Security - `hyva.getFormKey()` - Get/generate form key for POST requests - `hyva.getUenc()` - Base64 encode current URL for redirects - `hyva.postForm({action, data, skipUenc})` - Submit a POST form programmatically ### Cookies - `hyva.getCookie(name)` - Get cookie value (respects consent) - `hyva.setCookie(name, value, days, skipSetDomain)` - Set cookie - `hyva.setSessionC

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
1
Files Flagged
1
Chunks Analyzed
2
Analyzed
Feb 23, 2026, 06:51 AM
Security Audit — runlayer — hyva-alpine-component