skills/onmax/nuxt-skills/arkenv/Gen Agent Trust Hub

arkenv

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include commands for project setup and validation, specifically pnpm dlx arkenv init and arkenv check. These are standard CLI operations intended for initializing the library and verifying environment configurations.
  • [EXTERNAL_DOWNLOADS]: The skill references several Node.js packages including @arkenv/core, @arkenv/standard, @arkenv/vite-plugin, @arkenv/bun-plugin, @arkenv/nextjs, and @arkenv/nuxt, along with external validation libraries like zod and valibot. These are standard dependencies required for the library's functionality and framework integrations.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on project-specific data such as environment variable files and schema definitions (env.ts).
  • Ingestion points: Reads environment variable values and TypeScript schema definitions from the local project.
  • Boundary markers: The skill does not explicitly define prompt boundary markers or "ignore" instructions for the agent when processing these files.
  • Capability inventory: Performs file system modifications (scaffolding env.ts) and shell command execution via the arkenv CLI tool.
  • Sanitization: The primary purpose of the library is to provide validation and coercion for environment variables, which acts as a sanitization layer for the data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 11:20 AM
Security Audit — agent-trust-hub — arkenv