third-party-components
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains standard instructional language for an AI agent and does not attempt to override safety guidelines or bypass constraints.
- [EXTERNAL_DOWNLOADS]: The documentation includes examples of using the Vaadin
@NpmPackageannotation to manage dependencies. These are provided as template values for developers and do not represent a security risk within the skill's own execution context. - [COMMAND_EXECUTION]: No unauthorized or suspicious shell command execution was found. The skill uses standard Vaadin MCP tools for documentation lookup.
- [DATA_EXFILTRATION]: No patterns for unauthorized data access, credential harvesting, or exfiltration to external domains were detected.
- [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths are present in the provided files.
Audit Metadata