weapp-vite-vue-sfc-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content including Vue SFC files (.vue), script blocks (JSX/TSX), and local documentation files (AGENTS.md, dist/docs/vue-sfc.md). This content serves as an entry point for indirect prompt injection if it contains malicious instructions hidden within code or comments.
  • Ingestion points: User-supplied .vue files and project documentation files identified in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters to isolate external code content from its own instructional context.
  • Capability inventory: The agent is instructed to perform code analysis, recommend modifications, and provide troubleshooting steps based on the ingested content.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the processed files before the agent analyzes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:30 PM