third-party-components

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains standard instructional language for an AI agent and does not attempt to override safety guidelines or bypass constraints.
  • [EXTERNAL_DOWNLOADS]: The documentation includes examples of using the Vaadin @NpmPackage annotation to manage dependencies. These are provided as template values for developers and do not represent a security risk within the skill's own execution context.
  • [COMMAND_EXECUTION]: No unauthorized or suspicious shell command execution was found. The skill uses standard Vaadin MCP tools for documentation lookup.
  • [DATA_EXFILTRATION]: No patterns for unauthorized data access, credential harvesting, or exfiltration to external domains were detected.
  • [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths are present in the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 06:14 AM
Security Audit — agent-trust-hub — third-party-components