nodejs-queue-and-event-integration

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes security best practices by enforcing the transactional outbox pattern, which prevents 'dual-write' hazards where a database update succeeds but an event notification fails or vice versa.
  • [SAFE]: The instructions mandate explicit idempotency for all message consumers, requiring a deduplication key store to ensure that duplicate message deliveries (common in distributed systems) do not cause unintended side effects.
  • [SAFE]: The skill uses Zod for strict schema validation of all message envelopes and payloads upon both production and consumption, mitigating risks associated with processing untrusted or malformed data.
  • [SAFE]: Dependencies such as bullmq, kafkajs, and @aws-sdk/client-sqs are standard, industry-recognized packages for Node.js messaging integration. The use of testcontainers for integration testing is a best practice for verified infrastructure interactions.
  • [SAFE]: No unauthorized network operations, data exfiltration patterns, or obfuscation techniques were identified. The skill correctly utilizes the existing service scaffold's configuration, logging, and shutdown hooks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — nodejs-queue-and-event-integration