skills/midudev/autoskills/clerk-setup/Gen Agent Trust Hub

clerk-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes instructions from external web content to perform project modifications.
  • Ingestion points: Documentation URLs fetched via WebFetch from clerk.com, such as https://clerk.com/docs/nextjs/getting-started/quickstart.
  • Boundary markers: Absent. The prompt instructions do not specify delimiters or instructions to ignore potential commands within the external source.
  • Capability inventory: The skill executes package installations (npm install) and creates/modifies files including layout.tsx, middleware.ts, and .env.local.
  • Sanitization: The skill does not implement validation or filtering for the content retrieved from the documentation pages.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebFetch to download configuration guides from clerk.com and instructs the installation of official @clerk packages from the NPM registry. These resources are associated with a well-known technology provider.
  • [COMMAND_EXECUTION]: The skill automates the setup of authentication by running package manager commands and generating code files to integrate Clerk's SDK into the application.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-setup