clerk-setup
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages the
clerkCLI for core functionality, including initializing projects (clerk init), managing authenticated sessions (clerk auth login), linking applications (clerk link), and synchronizing environment variables (clerk env pull). These commands are standard administrative operations for the Clerk platform. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect instructions by fetching framework-specific quickstart guides from an external source.
- Ingestion points: Instructions are retrieved via the
WebFetchtool from subpaths ofhttps://clerk.com/docs/inSKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within the retrieved documentation.
- Capability inventory: The skill possesses the capability to install Node.js packages, write to local project files (such as
.env.localandmiddleware.ts), and execute CLI tools. - Sanitization: The skill processes information retrieved from the vendor's official documentation without performing additional verification or sanitization.
Audit Metadata