sanity-live-cache-components

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides architectural guidance and code snippets for integrating Sanity.io with Next.js applications using modern framework features like Cache Components. It follows established development patterns without introducing malicious code or instructions.\n- [DATA_EXFILTRATION]: The skill correctly handles sensitive credentials. It identifies SANITY_API_READ_TOKEN as a required environment variable and explicitly warns that this token must be kept server-side to prevent exposure in the client bundle. It uses standard environment variable access methods and implements a server-side check to ensure the token is present before execution.\n- [EXTERNAL_DOWNLOADS]: External dependencies and utility skills are sourced from well-known or trusted vendors. It suggests installing next-sanity (the official SDK for the skill's author) and utilizing official Next.js skills from Vercel's public repository. References to external documentation point to legitimate domains such as nextjs.org and github.com/vercel.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:16 AM
Security Audit — agent-trust-hub — sanity-live-cache-components