nuxt-studio
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables an AI-assisted editing and Git-publishing workflow for Markdown, MDC, and data files. This ingestion of external content constitutes a vulnerability surface where malicious instructions in content could potentially influence agent behavior during visual editing or AI-assisted transformations.
- Ingestion points: Reads repository source files including Markdown, MDC, YAML, and JSON into the editor context (documented in
references/live-editing.md). - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined in the provided instructions for processing external data.
- Capability inventory: The skill possesses the capability to commit drafts to Git and perform media uploads to local or external storage (documented in
references/deployment.mdandreferences/live-editing.md). - Sanitization: The editor serializes changes back to standard formats like Markdown and MDC during the publication cycle.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto install official Nuxt modules such asnuxt-studio,@nuxt/content, and@nuxthub/core. It also references documentation and setup guides from the officialnuxt.studiodomain, which are recognized as well-known resources in the Nuxt development ecosystem. - [COMMAND_EXECUTION]: The instructions provide standard development commands for the environment, including
npx nuxt module addfor module installation andnuxt buildfor preparing SSR-capable deployments.
Audit Metadata