formkit-core-skilld

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECREDENTIALS_UNSAFENO_CODE
Full Analysis
  • [CREDENTIALS_UNSAFE]: Example code snippets in documentation contain a hardcoded API key for the The Movie Database (TMDB) API (f48bcc9ed9cbce41f6c28ea181b67e14) in references/docs/inputs/autocomplete.md. This is a publicly known key used for demonstration purposes in technical documentation.
  • [PROMPT_INJECTION]: Static analysis tools flagged descriptions of "multi-step" form UI patterns as potential action concealment in references/docs/plugins/multi-step.md. These are false positives as the text describes standard user interface design to improve user experience on long forms.
  • [EXTERNAL_DOWNLOADS]: Multiple documentation files contain examples fetching data from external services such as api.themoviedb.org, image.tmdb.org, and api-formkit-docs-examples.formkit.workers.dev. These references are standard for demonstrating dynamic data loading in frontend components.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 02:47 AM
Security Audit — agent-trust-hub — formkit-core-skilld