integration-nuxt-3.6

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection surface.
  • Ingestion points: The agent is instructed in references/basic-integration-1.0-begin.md to select and read between 10 and 15 files from the target project to identify tracking opportunities.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions that might be embedded in the files it reads.
  • Capability inventory: The agent has permissions to edit project files (references/basic-integration-1.1-edit.md) and interact with the PostHog MCP to create dashboards and insights (references/basic-integration-1.3-conclude.md).
  • Sanitization: The skill lacks logic to sanitize or validate the content of processed project files before the agent executes code edits or external tool calls based on that data.
  • [EXTERNAL_DOWNLOADS]: Installation of vendor-owned libraries.
  • The documentation and example project (references/nuxt-js-3-6.md, references/EXAMPLE.md) provide instructions for installing official PostHog libraries (posthog-js and posthog-node) via standard package managers like npm, yarn, or pnpm.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 07:13 AM
Security Audit — agent-trust-hub — integration-nuxt-3.6