migrate-to-vinext
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run various shell commands including package manager installation (npm, yarn, pnpm, bun) and vinext-specific CLI tools for initialization, development, and deployment.
- [EXTERNAL_DOWNLOADS]: Migration requires downloading several packages from the NPM registry, such as vinext, vite, and nitro, and utilizes npx for running the compatibility check script.
- [INDIRECT_PROMPT_INJECTION]: The skill involves scanning user-provided project files (package.json, directory structure) to determine the migration path. This constitutes an ingestion point for external data that could influence agent behavior, though the risk is localized to the migration context.
- [SAFE]: The skill's behavior is consistent with its stated purpose as a migration utility. It uses standard industry tools and platforms (Vite, Cloudflare, Nitro) without any evidence of malicious intent or data exfiltration.
Audit Metadata