skills/nuxt/ui/nuxt-ui/Gen Agent Trust Hub

nuxt-ui

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation refers to the Nuxt UI MCP server at https://ui.nuxt.com/mcp and provides instructions to configure it in Cursor and Claude Code environments. These references point to official vendor-controlled infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a recipe for building AI chat interfaces that render streaming content from external AI models using the Comark markdown renderer. This creates a surface where untrusted data from an AI response is ingested and displayed in the user interface.
  • Ingestion points: Message streams and tool outputs handled by the useChat composable in pages/chat/[id].vue.
  • Boundary markers: The provided UI code does not include explicit security delimiters or prompt-level instructions to ignore embedded commands in the processed data.
  • Capability inventory: The implementation supports tool invocation and markdown rendering, including code block highlighting via Shiki.
  • Sanitization: Untrusted AI responses are processed through the Comark component for rendering into the DOM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:03 PM
Security Audit — agent-trust-hub — nuxt-ui