lov-install-tanstack-query

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local project files to identify patterns for automated refactoring.
  • Ingestion points: The skill uses rg and find to read package.json and source directories (src, app, etc.).
  • Boundary markers: No explicit delimiters are used when passing identified code segments to the agent context.
  • Capability inventory: The skill can execute package manager commands and write to TypeScript/JavaScript files.
  • Sanitization: No explicit validation of the ingested code is performed; users should review refactored output before committing.
  • [COMMAND_EXECUTION]: The skill executes standard development commands such as npm install, pnpm add, and tsc to manage dependencies and verify code integrity.
  • [EXTERNAL_DOWNLOADS]: The skill manages the installation of official @tanstack/react-query packages from public registries, which are well-known and trusted resources in the development community.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-install-tanstack-query