nuxt
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a coding assistant for Nuxt and Vue projects. By design, it processes user-provided code and files which could potentially contain malicious instructions intended to influence the agent's behavior. This is an inherent surface for developer-oriented skills.
- Ingestion points: Processes user-provided Nuxt code, components, and project structures (SKILL.md).
- Boundary markers: None present.
- Capability inventory: The skill provides a custom Vite plugin script (
tailwind-reference-plugin.js) and instructions for build-time configuration, but does not autonomously execute network or file-system operations outside the platform's standard tools. - Sanitization: None present.
- [COMMAND_EXECUTION]: The skill provides instructions to implement a custom Vite plugin (
rules/nuxt-and-tailwindcss.md) that performs string manipulation on source code during the application's build process. The script is legitimate tooling for managing TailwindCSS v4@referencedirectives and does not contain malicious logic.
Audit Metadata