mastra
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation guide and toolset for the Mastra framework, authored by the official vendor. Its instructions and provided scripts are aligned with standard software development and framework integration practices.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation from the mastra.ai domain and utilizes vendor-specific CLI tools via
npx(e.g.,mastra,@mastra/codemod). These resources originate from the framework's primary vendor and are used for documentation retrieval and project maintenance. - [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment checks (e.g.,
ls node_modules,npm list) and execute utility scripts (e.g.,scripts/provider-registry.mjs) to verify project configuration and model availability. These commands are localized and specific to the development workflow. - [CREDENTIALS_SAFE]: The skill provides instructions for managing sensitive information, such as API keys and database connection strings, through environment variables and
.envfiles. This follows industry-standard security practices for secret management. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external documentation and local source code to assist the user. While this creates a processing surface for untrusted data, the risk is inherent to the functionality of a coding assistant and is mitigated by the scope of the framework's intended use.
Audit Metadata