adopt-nuxtstart-changes
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to install additional components using
npx skills@latest add mattpocock/skills. This downloads and executes content from an external repository. - [COMMAND_EXECUTION]: The skill performs shell-based Git operations and executes the repository's build, test, and lint scripts during the verification phase.
- [EXTERNAL_DOWNLOADS]: The skill connects to the
nuxtstart/nuxtstartGitHub repository to fetch code updates and pruning metadata. - [PROMPT_INJECTION]: The skill is exposed to indirect prompt injection via external Git data from
nuxtstart/nuxtstart. While the process requires an adoption map and manual audit of changed paths to verify intent, malicious upstream content could potentially attempt to influence the agent's decisions or compromise the child repository.
Audit Metadata