vue-nuxt

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides defensive programming guidelines and security-focused patterns for Vue/Nuxt development. It does not contain any malicious instructions or backdoors.
  • [SAFE]: No hardcoded credentials, secrets, or sensitive file paths were detected. The skill explicitly instructs developers to keep secrets on the server-side and avoid exposing them in client-side configuration.
  • [SAFE]: All identified dependencies are standard, legitimate, and well-known packages in the JavaScript/Vue ecosystem. These include Vue, Nuxt, Vitest, Zod, DOMPurify, TresJS, and VueUse.
  • [SAFE]: The skill includes specific mitigations for known vulnerabilities (e.g., CVE-2024-34344 and CVE-2024-23657), demonstrating a proactive security posture.
  • [SAFE]: No obfuscation techniques, such as Base64-encoded commands, zero-width characters, or homoglyph attacks, were found in the skill content.
  • [SAFE]: The skill promotes secure coding practices, such as using v-text instead of v-html for unsanitized data, implementing Content Security Policy (CSP) headers, and using Zod for robust server-side input validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — vue-nuxt