nuxt-tanstack-mastery

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOW
Full Analysis
  • [Prompt Injection] (SAFE): No instructions found that attempt to bypass AI constraints or override safety protocols.- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file path access, or unauthorized network operations were identified.- [Unverifiable Dependencies & Remote Code Execution] (LOW): The skill includes a project bootstrap command using npx and npm install for standard libraries such as @tanstack/vue-query, @pinia/nuxt, and zod. These are widely trusted packages within the Vue/Nuxt ecosystem. Under the [TRUST-SCOPE-RULE], these findings are classified as LOW risk.- [Indirect Prompt Injection] (INFO): The skill is designed to perform code reviews and debugging on user-provided code. While this introduces an ingestion point for untrusted data, the skill lacks high-privilege capabilities (like file writing or command execution) that would make this surface exploitable.- [Obfuscation] (SAFE): No encoded content, zero-width characters, or homoglyphs were detected.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:12 PM