forms-router
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes implementation patterns for ingesting and processing user-provided data via web forms, which is the primary intended use case for this resource. The risk is mitigated by explicit guidance on validation and sanitization.
- Ingestion points: The skill provides templates for handling untrusted user input in files such as
references/integration-guide.mdandreferences/vanilla.md. - Boundary markers: While specific AI boundary markers are not included, the skill emphasizes strict data validation using Zod schemas.
- Capability inventory: Code examples include form submission via network operations using the
fetchAPI. - Sanitization: Comprehensive sanitization advice is provided in
references/security.md, specifically recommending the use ofDOMPurifyand proper output encoding. - [EXTERNAL_DOWNLOADS]: The skill's code examples reference several well-known and trusted third-party libraries for web development.
- Node.js Packages: Standard libraries such as
zod,react-hook-form,dompurify,@tanstack/react-form, andvee-validateare utilized for form management and security.
Audit Metadata