nuxt4-vue3-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The pattern demonstrated in app/pages/posts/[id].vue for dynamic SEO metadata generation creates a vulnerability surface by interpolating untrusted data into the document head.
  • Ingestion points: Data fetched from the /api/posts/[id] endpoint is processed in app/pages/posts/[id].vue using useAsyncData.
  • Boundary markers: The skill does not implement delimiters or instructions to ignore embedded prompts when rendering metadata.
  • Capability inventory: The skill utilizes useSeoMeta and useHead to populate page headers, which can be interpreted by AI-powered search crawlers and other automated agents.
  • Sanitization: The implementation employs a basic regular expression (.replace(/<[^>]*>/g, '')) to strip HTML tags, which is insufficient for preventing natural language prompt injection attacks designed to influence downstream LLMs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — nuxt4-vue3-patterns