fingerprint-vue
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard documentation and code snippets for integrating a third-party device identification service into a web application. The code follows established Vue 3 patterns for plugin registration and composable usage.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions correctly advise users to use environment variables for public API keys and explicitly warn against exposing secret API keys in frontend code, which is a key security best practice.
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates capturing device identification tokens and sending them to a backend API endpoint. While this involves data being passed to the backend, it is a standard identification workflow for fraud prevention services and does not pose a significant injection risk in this context.
Audit Metadata