security-and-hardening
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational resource for secure coding practices and does not contain any malicious patterns or vulnerabilities.
- [SAFE]: Code examples demonstrate the use of standard, reputable libraries such as bcrypt, zod, helmet, and dompurify to implement security controls.
- [SAFE]: The skill explicitly advises against dangerous practices like hardcoding secrets, using eval(), or trusting client-side validation.
- [SAFE]: It includes practical advice for secrets management, including .gitignore configurations and pre-commit checks.
- [SAFE]: The guidance on handling npm audit results is based on standard risk assessment principles.
Audit Metadata