vueuse-functions
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a large surface area for the ingestion of untrusted data from external sources without providing explicit security boundary markers or sanitization guidance.
- Ingestion points: Data enters the agent's context through functions documented in
references/useFetch.md(network requests),references/useWebSocket.md(real-time data),references/useClipboard.md(system clipboard), andreferences/useRouteQuery.md(URL parameters). - Boundary markers: Absent. Usage examples do not include delimiters or instructions to ignore embedded commands within fetched data.
- Capability inventory: The documented functions allow for arbitrary network operations, DOM manipulation, and state changes within the host application (e.g.,
executeinuseFetch,postinuseIpcRenderer). - Sanitization: The skill assumes standard Vue/Nuxt environments but does not instruct the agent on specific sanitization or validation of the fetched content before processing it further.
Audit Metadata