fingerprint-svelte

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install @fingerprint/svelte, which is an official package from the vendor (fingerprintjs). It also references documentation on docs.fingerprint.com, the official vendor domain. These are routine dependencies for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an ingestion surface where the agent processes device identification data (visitor_id, event_id) via the useVisitorData hook. This data is intended to be passed to internal API endpoints like /api/create-account. While this constitutes an external data ingestion point, the risk is negligible as these are structured identifiers generated by the vendor's SDK.
  • Ingestion points: useVisitorData hook in snippets/CreateAccountForm.svelte.
  • Boundary markers: None explicitly required for machine-generated identifiers.
  • Capability inventory: Performs a POST request to a local API endpoint using fetch.
  • Sanitization: Standard JSON stringification is used for the outgoing payload.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:34 PM
Security Audit — agent-trust-hub — fingerprint-svelte