backend-developer

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides high-quality scaffolding scripts for Express, FastAPI, Django, and Spring Boot. These scripts automate the creation of boilerplate code while encouraging security best practices like using 'helmet', 'cors', and 'bcrypt'.
  • [SAFE]: External references target well-known and trusted services, such as the Spring Initializr (start.spring.io), which is a standard industry tool for project bootstrapping.
  • [SAFE]: All identified credentials in the documentation and scripts (e.g., 'your-secret-key', 'password', 'postgres') are clearly marked placeholders or dummy values used for demonstration and template generation.
  • [SAFE]: Base64 encoded strings found in the Kubernetes documentation examples are the standard format for Kubernetes Secrets and do not contain hidden malicious logic.
  • [SAFE]: The deployment script ('deploy.sh') uses standard command-line interfaces for Docker, Kubernetes, AWS, and GCP to perform legitimate operations related to the skill's primary purpose.
  • [SAFE]: The skill implements strong input validation using libraries like Zod, express-validator, and Pydantic across its templates, reducing the risk of common vulnerabilities like SQL injection or mass assignment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 08:31 AM
Security Audit — agent-trust-hub — backend-developer