coss-svelte
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates the installation of UI components from the vendor's domain (
coss-sv.vercel.app) using the establishedshadcn-svelteutility. This follows standard industry practices for registry-based component distribution. - [SAFE]: All remote references and documentation links target the vendor's own infrastructure or well-known hosting services (Vercel, GitHub), which aligns with the skill's stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest documentation from external Markdown files hosted on the vendor's site. While this represents a data ingestion surface, the content originates from the official project repository and serves as necessary context for the agent's tasks.
- [SAFE]: No patterns of obfuscation, persistence, privilege escalation, or unauthorized data exfiltration were found within the skill's instructions or supporting reference files.
Audit Metadata