Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Pass3 providerslatest audit Feb 17, 2026
Independent checks from skills.sh's audit partners.
The skill provides architectural patterns for building AI agents using Trigger.dev and the Vercel AI SDK. It demonstrates legitimate orchestration patterns such as prompt chaining, parallelization, and evaluator-optimizer loops. No malicious code, data exfiltration, or obfuscation was detected. The code follows standard practices for the libraries mentioned. A minor security concern is the identified indirect prompt injection surface where user-provided input is interpolated directly into LLM prompts without delimiters or sanitization.
Detected behaviors
No alerts
No issues