svelte-flow

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides legitimate documentation and code snippets for using Svelte Flow (@xyflow/svelte), a common library for interactive diagrams.- [EXTERNAL_DOWNLOADS]: The skill references standard NPM packages such as @xyflow/svelte, @dagrejs/dagre, and html-to-image. These are well-known libraries in the web development ecosystem and are fetched from official package registries.- [INDIRECT_PROMPT_INJECTION]: The skill describes building UIs that ingest node and edge data (e.g., labels). While an agent could populate these from untrusted sources, Svelte Flow is a UI library and does not interpret these values as instructions, making the risk negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:43 PM
Security Audit — agent-trust-hub — svelte-flow