tanstack-start

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends using project-specific CLI tools and scripts for information retrieval and validation.\n
  • SKILL.md identifies maintenance scripts (python3 tools/skill/quick_validate.py) for validating skill integrity.\n
  • references/current-authority.md lists commands for the tanstack CLI and opensrc utility to fetch documentation and locate package source code.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements proactive security measures to prevent data leaks.\n
  • rules/error-handling.md explicitly forbids the exposure of provider secrets, raw webhooks, or internal stack traces in client-facing messages.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes an authority order that directs the agent to ingest data from external sources.\n
  • Ingestion points: Local node_modules source code, official documentation (via tanstack CLI), and GitHub repository content.\n
  • Boundary markers: Absent; the agent is instructed to treat these sources as authoritative.\n
  • Capability inventory: Command execution via python3 and the tanstack CLI.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 01:39 PM
Security Audit — agent-trust-hub — tanstack-start