ai-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to search local documentation and source files using shell commands like
grepand to manage dependencies using standard package managers likepnpm. - [EXTERNAL_DOWNLOADS]: Fetches model metadata from Vercel's official AI Gateway (
ai-gateway.vercel.sh) and searches technical documentation through the officialai-sdk.devdomain. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external documentation and local source files to provide accurate API information. While this creates an ingestion surface for potentially untrusted content, it is a standard requirement for technical documentation assistants.
- Ingestion points: Reads files from
node_modules/ai/docs/andnode_modules/ai/src/, and fetches content fromai-sdk.dev. - Boundary markers: Not explicitly defined in the provided snippets.
- Capability inventory: Uses
curlfor data retrieval,grepfor file searching, and package managers for library installation. - Sanitization: Relies on the agent's internal processing of documentation text.
Audit Metadata