tanstack-start
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill recommends using project-specific CLI tools and scripts for information retrieval and validation.\n
SKILL.mdidentifies maintenance scripts (python3 tools/skill/quick_validate.py) for validating skill integrity.\nreferences/current-authority.mdlists commands for thetanstackCLI andopensrcutility to fetch documentation and locate package source code.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements proactive security measures to prevent data leaks.\nrules/error-handling.mdexplicitly forbids the exposure of provider secrets, raw webhooks, or internal stack traces in client-facing messages.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes an authority order that directs the agent to ingest data from external sources.\n- Ingestion points: Local
node_modulessource code, official documentation (viatanstackCLI), and GitHub repository content.\n - Boundary markers: Absent; the agent is instructed to treat these sources as authoritative.\n
- Capability inventory: Command execution via
python3and thetanstackCLI.\n - Sanitization: Absent.
Audit Metadata