vite-plus
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows standard development practices for repository migration and toolchain configuration. No malicious command execution, data exfiltration, or obfuscation patterns were detected.
- [EXTERNAL_DOWNLOADS]: The skill references the
voidzero-dev/setup-vp@v1GitHub Action andvp upgradefunctionality, which are official components of the Vite+ ecosystem for managing the environment and updates. - [COMMAND_EXECUTION]: The skill utilizes the
vpCLI (e.g.,vp install,vp test,vp check) to perform development tasks. These commands are standard for the advertised purpose of frontend toolchain management. - [INDIRECT_PROMPT_INJECTION]: While the skill involves processing project files (like
package.jsonandvite.config.ts), this behavior is restricted to the intended migration workflow and does not introduce unsafe data handling or external control vectors.
Audit Metadata