skills/oakoss/agent-skills/vite/Gen Agent Trust Hub

vite

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill provides explicit security guidance in references/environment-variables.md regarding the handling of sensitive data. It correctly distinguishes between client-exposed variables (using the VITE_ prefix) and server-side secrets (which should not use the prefix and should be handled via loadEnv or process.env in configuration files). It further recommends using .env.local files, which are conventionally git-ignored, to prevent accidental credential leakage.
  • [DYNAMIC_EXECUTION]: The skill documents legitimate dynamic execution patterns inherent to Vite, such as asynchronous configuration loading in vite.config.ts and the use of the transform and load hooks in the plugin API. These are standard features of the build tool and are presented with appropriate technical context.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how Vite ingests and processes various project files (HTML, CSS, JS, and .env). While these ingestion points represent an attack surface for the underlying build tool, the skill includes necessary boundary markers and warnings (e.g., security considerations for environment variables) to help developers maintain a secure configuration. The capabilities described (like dev server proxies and SSR) are restricted to the intended local development and build environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — vite