tanstack-start

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading various React, TanStack, and Cloudflare-related packages from the NPM registry and using the shadcn/ui CLI. These resources are from trusted organizations and well-known services.
  • [COMMAND_EXECUTION]: To initialize the project and manage its lifecycle, the skill involves executing shell commands for package installation, database migrations, and Cloudflare Workers deployment. These actions are standard for the intended full-stack development workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill generates application code based on user-provided project metadata (e.g., name, description, authentication preferences). While this is a requirement for its functionality, it introduces an attack surface for indirect prompt injection via the provided project details.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:23 PM