nodejs-service-scaffold

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a 'Secure by Default' posture, specifically instructing the agent to ensure no secrets or credentials are baked into source code, environment templates, or container images.
  • [SAFE]: It enforces strict dependency management by requiring exact version pinning (no '^' or '~') in package.json to ensure build reproducibility and prevent supply chain drift.
  • [SAFE]: The configuration logic uses schema validation (Zod) to fail-fast during the boot process if required environment variables are missing or malformed, preventing runtime errors related to undefined configuration.
  • [SAFE]: Containerization instructions specify multi-stage Dockerfiles that run as a non-root user and use digest-pinned base images, significantly reducing the attack surface of the deployed service.
  • [SAFE]: The skill includes comprehensive error handling across multiple tiers (process-level, framework-level, and graceful shutdown) and ensures that internal stack traces are not leaked in non-development environments.
  • [SAFE]: Automated build verification steps (type-checking, linting, and smoke tests) are required before completing the scaffold, ensuring the generated code is functional and compliant with standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — nodejs-service-scaffold