lit-dev
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install common, reputable development dependencies from the NPM registry, such as
lit,zod,typescript, and@playwright/test. These are standard tools for the described tech stack. - [COMMAND_EXECUTION]: Includes routine shell commands for project scaffolding and file management, such as
pnpm create turbo,mkdir, andtouch. These commands are standard for project setup and do not involve suspicious parameters. - [DYNAMIC_EXECUTION]: The skill mentions the
unsafeStaticdirective in the context oflit/static-html.js. It properly identifies this as a potential security risk and includes a clear warning that it must only be used with trusted, developer-controlled content to prevent XSS. - [DATA_EXFILTRATION]: Demonstrates data fetching using
fetchwithin a@lit/taskexample targetingexample.com. This is a benign educational pattern for illustrating asynchronous component logic. - [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling external data through properties and API calls. It correctly relies on Lit's
htmltagged templates, which provide default sanitization and protection against common web injection attacks like XSS.
Audit Metadata