svelte
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The README.md documentation suggests using
npx frontend-standard-skillsfor project setup. This command downloads and executes a utility package from the npm registry. As this tool is provided by the skill's author to facilitate the implementation of the defined standards, it is consistent with the skill's purpose. - [COMMAND_EXECUTION]: The skill references standard shell commands for project maintenance, including package installation (
npm install), linting (eslint), type checking (svelte-check), and various testing frameworks (vitest,playwright). These are intended for use by developers in their local environment. - [PROMPT_INJECTION]: The skill instructs the agent to analyze user-provided code, which creates a surface for indirect prompt injection. Untrusted data enters the agent context through Svelte component files and route scripts. The skill currently lacks explicit boundary markers (delimiters) or instructions for the agent to ignore embedded commands within the analyzed code, though the agent's inherent capabilities and platform-level guardrails mitigate this risk.
Audit Metadata