nuxt-ui
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation refers to the Nuxt UI MCP server at
https://ui.nuxt.com/mcpand provides instructions to configure it in Cursor and Claude Code environments. These references point to official vendor-controlled infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill provides a recipe for building AI chat interfaces that render streaming content from external AI models using the
Comarkmarkdown renderer. This creates a surface where untrusted data from an AI response is ingested and displayed in the user interface. - Ingestion points: Message streams and tool outputs handled by the
useChatcomposable inpages/chat/[id].vue. - Boundary markers: The provided UI code does not include explicit security delimiters or prompt-level instructions to ignore embedded commands in the processed data.
- Capability inventory: The implementation supports tool invocation and markdown rendering, including code block highlighting via Shiki.
- Sanitization: Untrusted AI responses are processed through the
Comarkcomponent for rendering into the DOM.
Audit Metadata