nuxt-tanstack-mastery
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOW
Full Analysis
- [Prompt Injection] (SAFE): No instructions found that attempt to bypass AI constraints or override safety protocols.- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file path access, or unauthorized network operations were identified.- [Unverifiable Dependencies & Remote Code Execution] (LOW): The skill includes a project bootstrap command using
npxandnpm installfor standard libraries such as@tanstack/vue-query,@pinia/nuxt, andzod. These are widely trusted packages within the Vue/Nuxt ecosystem. Under the [TRUST-SCOPE-RULE], these findings are classified as LOW risk.- [Indirect Prompt Injection] (INFO): The skill is designed to perform code reviews and debugging on user-provided code. While this introduces an ingestion point for untrusted data, the skill lacks high-privilege capabilities (like file writing or command execution) that would make this surface exploitable.- [Obfuscation] (SAFE): No encoded content, zero-width characters, or homoglyphs were detected.
Audit Metadata