adopt-nuxtstart-changes

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to install additional components using npx skills@latest add mattpocock/skills. This downloads and executes content from an external repository.
  • [COMMAND_EXECUTION]: The skill performs shell-based Git operations and executes the repository's build, test, and lint scripts during the verification phase.
  • [EXTERNAL_DOWNLOADS]: The skill connects to the nuxtstart/nuxtstart GitHub repository to fetch code updates and pruning metadata.
  • [PROMPT_INJECTION]: The skill is exposed to indirect prompt injection via external Git data from nuxtstart/nuxtstart. While the process requires an adoption map and manual audit of changed paths to verify intent, malicious upstream content could potentially attempt to influence the agent's decisions or compromise the child repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 02:59 AM
Security Audit — agent-trust-hub — adopt-nuxtstart-changes