clerk-nuxt-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: There is a discrepancy between the stated author of the skill ('midudev') and the metadata field in the SKILL.md file ('author: clerk'). While common for developers creating third-party integrations, this inconsistency is noted as metadata poisoning.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data, specifically user profile information (names, emails, avatars) from the Clerk API, which could be exploited for indirect prompt injection attacks.
  • Ingestion points: External data is brought into the application context via the useUser composable in references/composables.md and through clerkClient in references/server-api-routes.md.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions in the user data are provided.
  • Capability inventory: The skill uses the WebFetch tool for external API interaction and standard file system tools to create and manage the Nuxt project structure.
  • Sanitization: There is no mention of sanitization, validation, or escaping of the user-provided data before it is rendered in components or processed in server-side logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-nuxt-patterns