vue
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of architectural guidelines and developer workflows for Vue.js. All instructions are pedagogical or procedural, focusing on project structure and framework conventions. No unauthorized network activity or credential harvesting patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection through the analysis of external code. (1) Ingestion points: The agent ingests user-provided Vue source code, components, and project directories as specified in SKILL.md. (2) Boundary markers: No specific delimiters or instructions to ignore embedded commands in the processed data are defined. (3) Capability inventory: The skill references standard shell commands (npm run test, npm run build, npx vite preview) in references/workflows.md for project verification. (4) Sanitization: There is no explicit sanitization or filtering of the content within the Vue components being reviewed.
Audit Metadata