clerk-tanstack-patterns
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: The skill's YAML frontmatter attributes the author as 'clerk', which contradicts the system context identifying the author as 'midudev'. This represents deceptive metadata that could mislead users regarding the origin and maintenance of the code patterns provided.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a coding assistant for routing and authentication logic, creating a surface for indirect prompt injection based on user requirements.\n
- Ingestion points: User-provided application descriptions and route specifications (as seen in the
evals.jsonprompts andSKILL.mdguidance).\n - Boundary markers: Absent; the instructions lack delimiters or explicit directives to ignore instructions that might be embedded in user-supplied data.\n
- Capability inventory: The skill has
WebFetchtool access and generates functional code for route guards, server functions, and environment configuration.\n - Sanitization: The provided patterns use standard security mechanisms like
beforeLoadand server-side authentication, but the skill does not show validation or sanitization of user-provided inputs used to construct these guards.\n- [EXTERNAL_DOWNLOADS]: Thepackage.jsonin thetemplates/tanstack-basic-auth/directory specifies 'latest' for several core dependencies from well-known providers like Clerk and TanStack. Using unpinned versions is a supply chain risk that allows the inclusion of new package updates without manual verification of their integrity.
Audit Metadata