skills/celeroncoder/skills/ai-sdk/Gen Agent Trust Hub

ai-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to search local documentation and source files using shell commands like grep and to manage dependencies using standard package managers like pnpm.
  • [EXTERNAL_DOWNLOADS]: Fetches model metadata from Vercel's official AI Gateway (ai-gateway.vercel.sh) and searches technical documentation through the official ai-sdk.dev domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external documentation and local source files to provide accurate API information. While this creates an ingestion surface for potentially untrusted content, it is a standard requirement for technical documentation assistants.
  • Ingestion points: Reads files from node_modules/ai/docs/ and node_modules/ai/src/, and fetches content from ai-sdk.dev.
  • Boundary markers: Not explicitly defined in the provided snippets.
  • Capability inventory: Uses curl for data retrieval, grep for file searching, and package managers for library installation.
  • Sanitization: Relies on the agent's internal processing of documentation text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — ai-sdk