nuxt4-vue3-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The pattern demonstrated in
app/pages/posts/[id].vuefor dynamic SEO metadata generation creates a vulnerability surface by interpolating untrusted data into the document head. - Ingestion points: Data fetched from the
/api/posts/[id]endpoint is processed inapp/pages/posts/[id].vueusinguseAsyncData. - Boundary markers: The skill does not implement delimiters or instructions to ignore embedded prompts when rendering metadata.
- Capability inventory: The skill utilizes
useSeoMetaanduseHeadto populate page headers, which can be interpreted by AI-powered search crawlers and other automated agents. - Sanitization: The implementation employs a basic regular expression (
.replace(/<[^>]*>/g, '')) to strip HTML tags, which is insufficient for preventing natural language prompt injection attacks designed to influence downstream LLMs.
Audit Metadata