vueuse-functions

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents functions that ingest data from potentially untrusted external surfaces.
  • Ingestion points: The skill references useUrlSearchParams.md, useClipboard.md, useStorage.md, and useFetch.md, which pull data from browser query strings, the system clipboard, browser storage, and network responses respectively.
  • Boundary markers: Usage examples in the documentation lack explicit boundary markers or instructions to ignore embedded commands.
  • Capability inventory: The skill documents capabilities such as useFetch and useAxios (network requests), useFileSystemAccess (local file interaction), and useScriptTag (dynamic JavaScript loading).
  • Sanitization: The provided usage examples do not demonstrate input sanitization or validation before processing external data.
  • [EXTERNAL_DOWNLOADS]: The documentation references and recommends the installation of various third-party libraries from official registries, including async-validator, axios, change-case, universal-cookie, drauu, focus-trap, fuse.js, idb-keyval, jwt-decode, nprogress, and qrcode.
  • [DYNAMIC_EXECUTION]: The skill documents the useScriptTag and useWebWorkerFn composables, which enable the application to load external scripts at runtime and execute functions within Web Workers, representing powerful execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:36 AM
Security Audit — agent-trust-hub — vueuse-functions