skills/klh/skills/lit-dev/Gen Agent Trust Hub

lit-dev

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install common, reputable development dependencies from the NPM registry, such as lit, zod, typescript, and @playwright/test. These are standard tools for the described tech stack.
  • [COMMAND_EXECUTION]: Includes routine shell commands for project scaffolding and file management, such as pnpm create turbo, mkdir, and touch. These commands are standard for project setup and do not involve suspicious parameters.
  • [DYNAMIC_EXECUTION]: The skill mentions the unsafeStatic directive in the context of lit/static-html.js. It properly identifies this as a potential security risk and includes a clear warning that it must only be used with trusted, developer-controlled content to prevent XSS.
  • [DATA_EXFILTRATION]: Demonstrates data fetching using fetch within a @lit/task example targeting example.com. This is a benign educational pattern for illustrating asynchronous component logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling external data through properties and API calls. It correctly relies on Lit's html tagged templates, which provide default sanitization and protection against common web injection attacks like XSS.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 01:12 PM
Security Audit — agent-trust-hub — lit-dev