learning-astro
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as an interactive educational co-pilot. It provides step-by-step guidance for setting up an Astro project using official CLI commands (
npm create astro@latest,npx astro add). - [SAFE]: All external references point to well-known and trusted domains such as
astro.build,docs.astro.build,nodejs.org, andvalidator.w3.org. - [SAFE]: The code snippets provided for components, layouts, and content collections follow best practices for the Astro framework (Astro 6.x) and include standard Zod schema validation for content safety.
- [SAFE]: No obfuscation, prompt injection, or persistence mechanisms were found. The skill includes a documentation search tool (
mcp__astro-docs__search_astro_docs) which is a standard method for accessing up-to-date technical information. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with user-provided project files to recap progress and provide troubleshooting assistance. While this creates a theoretical ingestion point for untrusted data, it is a primary functional requirement of a developer co-pilot and is handled via instructional guidance rather than automated execution of untrusted input.
Audit Metadata