integration-nuxt-3.6
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection surface.
- Ingestion points: The agent is instructed in
references/basic-integration-1.0-begin.mdto select and read between 10 and 15 files from the target project to identify tracking opportunities. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions that might be embedded in the files it reads.
- Capability inventory: The agent has permissions to edit project files (
references/basic-integration-1.1-edit.md) and interact with the PostHog MCP to create dashboards and insights (references/basic-integration-1.3-conclude.md). - Sanitization: The skill lacks logic to sanitize or validate the content of processed project files before the agent executes code edits or external tool calls based on that data.
- [EXTERNAL_DOWNLOADS]: Installation of vendor-owned libraries.
- The documentation and example project (
references/nuxt-js-3-6.md,references/EXAMPLE.md) provide instructions for installing official PostHog libraries (posthog-jsandposthog-node) via standard package managers like npm, yarn, or pnpm.
Audit Metadata