nuxt-content
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process content from various external sources including local files, remote Git repositories, and custom APIs. This ingestion of untrusted data creates a vulnerability surface for indirect prompt injection.
- Ingestion points: The skill uses Git repositories (references/collections.md) and external APIs via $fetch (references/advanced.md) as primary content sources.
- Boundary markers: While the skill uses Zod for data schema validation, there are no specific markers used to isolate natural language instructions from the content being processed.
- Capability inventory: The skill has the capability to perform network fetches, read from the file system, and write to database adapters like SQLite and PostgreSQL.
- Sanitization: Content is validated for structural correctness via Zod schemas, but natural language content is not sanitized for potential injection patterns.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of content from external repositories and services during the build process.
- Evidence: The configuration in references/collections.md supports fetching from GitHub URLs (e.g., https://github.com/org/docs), and references/advanced.md demonstrates fetching release data from external API endpoints.
- [CREDENTIALS_UNSAFE]: The skill promotes security best practices by instructing users to manage sensitive credentials such as Git tokens and database connection strings using environment variables.
- Evidence: Instructions in references/collections.md advise using process.env.DOCS_TOKEN for repository authentication, and references/config.md advises keeping database credentials in private runtime configuration.
Audit Metadata