tanstack-stack

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No instructions were found that attempt to override agent behavior, bypass safety filters, or extract system prompts.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private tokens are present; code examples use standard placeholders where appropriate.
  • [EXTERNAL_DOWNLOADS]: All external references and package installations target well-known, official sources from the TanStack and Effect-TS organizations.
  • [REMOTE_CODE_EXECUTION]: No patterns of executing remote scripts or unverified code were identified.
  • [COMMAND_EXECUTION]: Shell commands are restricted to standard project initialization and package management tasks (e.g., npm install, npm create).
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized data collection or exfiltration of sensitive information to external domains.
  • [DATA_EXPOSURE]: The skill does not attempt to access sensitive local files, environment variables, or system configurations.
  • [SAFE]: The skill serves as a legitimate technical guide, encouraging the use of runtime validation and type safety to improve application security and stability.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:24 AM
Security Audit — agent-trust-hub — tanstack-stack