skills/mastra-ai/skills/mastra/Gen Agent Trust Hub

mastra

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation guide and toolset for the Mastra framework, authored by the official vendor. Its instructions and provided scripts are aligned with standard software development and framework integration practices.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation from the mastra.ai domain and utilizes vendor-specific CLI tools via npx (e.g., mastra, @mastra/codemod). These resources originate from the framework's primary vendor and are used for documentation retrieval and project maintenance.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment checks (e.g., ls node_modules, npm list) and execute utility scripts (e.g., scripts/provider-registry.mjs) to verify project configuration and model availability. These commands are localized and specific to the development workflow.
  • [CREDENTIALS_SAFE]: The skill provides instructions for managing sensitive information, such as API keys and database connection strings, through environment variables and .env files. This follows industry-standard security practices for secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external documentation and local source code to assist the user. While this creates a processing surface for untrusted data, the risk is inherent to the functionality of a coding assistant and is mitigated by the scope of the framework's intended use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 07:08 PM
Security Audit — agent-trust-hub — mastra