nodejs-service-scaffold
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a 'Secure by Default' posture, specifically instructing the agent to ensure no secrets or credentials are baked into source code, environment templates, or container images.
- [SAFE]: It enforces strict dependency management by requiring exact version pinning (no '^' or '~') in package.json to ensure build reproducibility and prevent supply chain drift.
- [SAFE]: The configuration logic uses schema validation (Zod) to fail-fast during the boot process if required environment variables are missing or malformed, preventing runtime errors related to undefined configuration.
- [SAFE]: Containerization instructions specify multi-stage Dockerfiles that run as a non-root user and use digest-pinned base images, significantly reducing the attack surface of the deployed service.
- [SAFE]: The skill includes comprehensive error handling across multiple tiers (process-level, framework-level, and graceful shutdown) and ensures that internal stack traces are not leaked in non-development environments.
- [SAFE]: Automated build verification steps (type-checking, linting, and smoke tests) are required before completing the scaffold, ensuring the generated code is functional and compliant with standards.
Audit Metadata