nuqs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and code examples for 'nuqs', a legitimate library for managing URL query state. All analyzed files contain standard React/Next.js implementation patterns.
- [SAFE]: Build and validation scripts listed in
README.md(pnpm build,pnpm validate) are routine tasks for maintaining a markdown-based documentation skill and do not perform suspicious operations. - [SAFE]: External dependencies and references point to official documentation domains (nuqs.dev, nextjs.org, react.dev) and well-known, trusted organizations on GitHub.
- [INDIRECT_PROMPT_INJECTION]: The skill provides guidelines for handling URL parameters, which represent a data ingestion surface. However, the skill mitigates this risk by providing extensive rules for sanitization and validation:
- Ingestion points: URL
searchParamsanduseQueryStatehooks (documented acrossreferences/). - Boundary markers: Recommends the use of
Standard Schema(Zod, Valibot) to define strict data boundaries (references/state-standard-schema.md). - Capability inventory: The skill restricts actions to UI state management and server-side fetching; it does not include capabilities for arbitrary command execution or unauthorized network operations.
- Sanitization: Includes mandatory validation for JSON parsers (
references/parser-json-validation.md) and enum constraints (references/parser-enum-validation.md) to ensure only expected data shapes are processed.
Audit Metadata