vercel-composition-patterns

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No attempts to override system prompts or bypass safety filters were found. The instructional language is standard for a coding guide.- [Data Exposure & Exfiltration] (SAFE): No hardcoded secrets, API keys, or sensitive file paths are present. There are no network-related commands (curl, wget, etc.).- [Obfuscation] (SAFE): All content is human-readable markdown. No Base64, zero-width characters, or other obfuscation techniques were identified.- [Unverifiable Dependencies & RCE] (SAFE): The skill does not include any package manager files (package.json, requirements.txt) or commands to install/execute external scripts.- [Privilege Escalation] (SAFE): No commands involving sudo, chmod, or system configuration modifications are present.- [Persistence Mechanisms] (SAFE): The skill does not attempt to modify shell profiles, cron jobs, or startup services.- [Indirect Prompt Injection] (SAFE): While the skill defines rules for processing code, it does not ingest untrusted external data or provide a surface for third-party instructions to influence the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:04 PM