clerk-nuxt-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: There is a discrepancy between the stated author of the skill ('midudev') and the metadata field in the
SKILL.mdfile ('author: clerk'). While common for developers creating third-party integrations, this inconsistency is noted as metadata poisoning. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data, specifically user profile information (names, emails, avatars) from the Clerk API, which could be exploited for indirect prompt injection attacks.
- Ingestion points: External data is brought into the application context via the
useUsercomposable inreferences/composables.mdand throughclerkClientinreferences/server-api-routes.md. - Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions in the user data are provided.
- Capability inventory: The skill uses the
WebFetchtool for external API interaction and standard file system tools to create and manage the Nuxt project structure. - Sanitization: There is no mention of sanitization, validation, or escaping of the user-provided data before it is rendered in components or processed in server-side logic.
Audit Metadata