astro-assets
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard instructional content for the Astro framework asset management system, following official documentation patterns.
- [SAFE]: The instructions include a security best practice warning to avoid placing secrets or sensitive configuration in the
public/directory, as these files are served verbatim and are not processed by the build pipeline. - [PROMPT_INJECTION]: The skill describes workflows for processing external project assets and configurations. 1. Ingestion points: Local asset files (images, fonts) and project configuration files (astro.config.mjs). 2. Boundary markers: Relies on native Astro build constraints and explicit asset imports. 3. Capability inventory: Build-time asset optimization, file hashing, and manifest generation. 4. Sanitization: Instructions specifically recommend using allow-lists for remote image domains and sanitization for SVGs to mitigate risks. This surface is categorized as safe due to the use of standard framework-native security controls.
Audit Metadata