skills/pproenca/dot-skills/nuqs/Gen Agent Trust Hub

nuqs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for 'nuqs', a legitimate library for managing URL query state. All analyzed files contain standard React/Next.js implementation patterns.
  • [SAFE]: Build and validation scripts listed in README.md (pnpm build, pnpm validate) are routine tasks for maintaining a markdown-based documentation skill and do not perform suspicious operations.
  • [SAFE]: External dependencies and references point to official documentation domains (nuqs.dev, nextjs.org, react.dev) and well-known, trusted organizations on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides guidelines for handling URL parameters, which represent a data ingestion surface. However, the skill mitigates this risk by providing extensive rules for sanitization and validation:
  • Ingestion points: URL searchParams and useQueryState hooks (documented across references/).
  • Boundary markers: Recommends the use of Standard Schema (Zod, Valibot) to define strict data boundaries (references/state-standard-schema.md).
  • Capability inventory: The skill restricts actions to UI state management and server-side fetching; it does not include capabilities for arbitrary command execution or unauthorized network operations.
  • Sanitization: Includes mandatory validation for JSON parsers (references/parser-json-validation.md) and enum constraints (references/parser-enum-validation.md) to ensure only expected data shapes are processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:03 PM
Security Audit — agent-trust-hub — nuqs