vite
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill provides explicit security guidance in
references/environment-variables.mdregarding the handling of sensitive data. It correctly distinguishes between client-exposed variables (using theVITE_prefix) and server-side secrets (which should not use the prefix and should be handled vialoadEnvorprocess.envin configuration files). It further recommends using.env.localfiles, which are conventionally git-ignored, to prevent accidental credential leakage. - [DYNAMIC_EXECUTION]: The skill documents legitimate dynamic execution patterns inherent to Vite, such as asynchronous configuration loading in
vite.config.tsand the use of thetransformandloadhooks in the plugin API. These are standard features of the build tool and are presented with appropriate technical context. - [INDIRECT_PROMPT_INJECTION]: The skill documents how Vite ingests and processes various project files (HTML, CSS, JS, and
.env). While these ingestion points represent an attack surface for the underlying build tool, the skill includes necessary boundary markers and warnings (e.g., security considerations for environment variables) to help developers maintain a secure configuration. The capabilities described (like dev server proxies and SSR) are restricted to the intended local development and build environment.
Audit Metadata