nuxt

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a coding assistant for Nuxt and Vue projects. By design, it processes user-provided code and files which could potentially contain malicious instructions intended to influence the agent's behavior. This is an inherent surface for developer-oriented skills.
  • Ingestion points: Processes user-provided Nuxt code, components, and project structures (SKILL.md).
  • Boundary markers: None present.
  • Capability inventory: The skill provides a custom Vite plugin script (tailwind-reference-plugin.js) and instructions for build-time configuration, but does not autonomously execute network or file-system operations outside the platform's standard tools.
  • Sanitization: None present.
  • [COMMAND_EXECUTION]: The skill provides instructions to implement a custom Vite plugin (rules/nuxt-and-tailwindcss.md) that performs string manipulation on source code during the application's build process. The script is legitimate tooling for managing TailwindCSS v4 @reference directives and does not contain malicious logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 09:44 AM
Security Audit — agent-trust-hub — nuxt