svelte-template-syntax

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely educational, consisting of Markdown files that document Svelte 5 features such as block logic, snippets, and attribute bindings.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The language is purely instructional and focused on the Svelte framework.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or suspicious network exfiltration logic were found. Network examples (e.g., in await expressions) use localized API paths like /api/users/.
  • [REMOTE_CODE_EXECUTION]: There are no commands to download or execute external scripts, and no package managers (npm/pip) are invoked to install untrusted dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents features that handle external data ({@html}, createRawSnippet). While these are injection surfaces, the documentation proactively warns about XSS risks and recommends the use of sanitization libraries.
  • [COMMAND_EXECUTION]: No shell command execution or dynamic context injection (!command) patterns were found in the SKILL.md or supporting files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:24 AM
Security Audit — agent-trust-hub — svelte-template-syntax