tanstack-query-react-nextjs-implementation
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of markdown documentation and architectural patterns. It does not include any scripts, commands, or automated installers, which significantly reduces the risk of direct malicious execution.
- [CREDENTIALS_UNSAFE]: The documentation actively promotes security best practices by instructing developers to avoid placing secrets in
NEXT_PUBLIC_*variables and prohibiting the inclusion of authentication tokens or private session data in query keys. - [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to analyze external project resources such as OpenAPI definitions and repository configuration files (
.itsol.md). While this ingestion of untrusted data is a theoretical attack surface common to coding assistants, the skill encourages validation and backend-centric authorization, which mitigates potential impacts.
Audit Metadata