use-vp-config

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of the @liangmi/vp-config package from a package registry.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the vp (Vite+) CLI tool for project setup, configuration validation, and running development tasks (e.g., vp install, vp config, vp check).
  • [PROMPT_INJECTION]: The skill requires the agent to ingest content from repository files such as AGENTS.md and package.json, which represents an indirect prompt injection surface. 1. Ingestion points: AGENTS.md, package.json, and vite.config.ts. 2. Boundary markers: Absent. 3. Capability inventory: Command execution via vp CLI. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 02:42 AM
Security Audit — agent-trust-hub — use-vp-config