Back to skill

Security audit

Vue3 Project Standard

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Vue 3 project-standards skill with no executable install behavior or hidden data handling.

Use this as a general Vue 3 architecture convention skill. Review its auth-token examples before applying them in a production app, and prefer the named specialist skills for security, testing, accessibility, forms, or data-fetching decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description is broadly scoped across many common Vue 3 architecture, components, routing, Pinia, API, and styling tasks, which can cause the skill to activate for routine requests that should be handled by narrower or safer specialist skills. In agentic environments, over-broad activation increases the chance of misrouting user prompts, unnecessary exposure of repository context, and bypass of more appropriate domain-specific review workflows such as security or testing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.