vue-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for rendering dynamic HTML content which serves as an ingestion point for potentially malicious data.
- Ingestion points: User-provided or external content passed to components and rendered via the
v-htmldirective as described inreferences/sfc.md. - Boundary markers: The skill strongly recommends the use of standard template interpolation
{{ }}for safe, escaped rendering by default and identifiesv-htmlas dangerous. - Capability inventory: The instructions involve browser-side script execution capabilities inherent to the
v-htmldirective. - Sanitization: The documentation explicitly mandates the use of
DOMPurifyto sanitize HTML before rendering and provides clear warnings against usingv-htmlwith untrusted content, mitigating the potential for script injection. - [EXTERNAL_DOWNLOADS]: The skill recommends several third-party libraries for performance optimization and utility, including
vue-virtual-scroller,@tanstack/vue-virtual,gsap,dompurify,lodash-es, and@vueuse/core. These are widely recognized and standard utilities within the JavaScript and Vue.js ecosystem for features like virtualization and secure rendering.
Audit Metadata