skills/ericrisco/rsc-harness/svelte/Gen Agent Trust Hub

svelte

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical reference for Svelte 5 and SvelteKit development, providing accurate information on state management, server-side rendering, and project structure.
  • [COMMAND_EXECUTION]: The skill includes a verification script (scripts/verify.sh) designed to run within the user's SvelteKit project. It executes standard development commands including svelte-check, tsc --noEmit, vitest, and vite build to validate code quality and build success. The script uses npx --no-install and local package managers to ensure it only runs tools already present in the user's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains logic to inspect the local project environment to provide contextually relevant advice.
  • Ingestion points: The skill reads package.json and svelte.config.js to determine the Svelte version and compiler configuration.
  • Boundary markers: The instructions provide clear separation between Svelte 4 (legacy) and Svelte 5 (runes) patterns to prevent code incompatibility.
  • Capability inventory: The scripts/verify.sh script executes shell commands to perform type checking, unit testing, and production builds.
  • Sanitization: The verification script implements checks to verify the existence of tools before execution and avoids unexpected network downloads by using --no-install flags.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — svelte