better-auth-components
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains a command to download a markdown file from
https://fullstackrecipes.com/recipes/better-auth-components.md. This fetches content from an external domain not included in the trusted provider list. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted markdown data from an external URL which is then processed by the agent. This creates a surface where malicious instructions could be embedded in the remote file to influence agent behavior.
- Ingestion points: Content is fetched from
https://fullstackrecipes.com/recipes/better-auth-components.md(referenced inSKILL.md). - Boundary markers: None identified in the skill instructions to delimit the external content.
- Capability inventory: The skill facilitates the retrieval of external text which the agent will subsequently parse and act upon.
- Sanitization: No validation or filtering of the remote content is performed before processing.
Audit Metadata