vueuse-functions
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents functions that ingest data from potentially untrusted external surfaces.
- Ingestion points: The skill references
useUrlSearchParams.md,useClipboard.md,useStorage.md, anduseFetch.md, which pull data from browser query strings, the system clipboard, browser storage, and network responses respectively. - Boundary markers: Usage examples in the documentation lack explicit boundary markers or instructions to ignore embedded commands.
- Capability inventory: The skill documents capabilities such as
useFetchanduseAxios(network requests),useFileSystemAccess(local file interaction), anduseScriptTag(dynamic JavaScript loading). - Sanitization: The provided usage examples do not demonstrate input sanitization or validation before processing external data.
- [EXTERNAL_DOWNLOADS]: The documentation references and recommends the installation of various third-party libraries from official registries, including
async-validator,axios,change-case,universal-cookie,drauu,focus-trap,fuse.js,idb-keyval,jwt-decode,nprogress, andqrcode. - [DYNAMIC_EXECUTION]: The skill documents the
useScriptTaganduseWebWorkerFncomposables, which enable the application to load external scripts at runtime and execute functions within Web Workers, representing powerful execution capabilities.
Audit Metadata