frappe-patterns

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive development guide and pattern library for the Frappe Framework and ERPNext. All code snippets follow framework conventions and industry best practices.
  • [COMMAND_EXECUTION]: Provides documentation for the 'bench' CLI tool, which is the standard management interface for Frappe environments. The commands provided (e.g., bench export-fixtures, bench console) are legitimate administrative operations.
  • [EXTERNAL_DOWNLOADS]: References official documentation and GitHub repositories for Frappe, ERPNext, and Frappe UI. It also includes an integration pattern for Razorpay, a well-known payment gateway service.
  • [CREDENTIALS_UNSAFE]: Correctly identifies hardcoding credentials as an anti-pattern and demonstrates the secure method for retrieving encrypted passwords via the framework's internal 'get_password' method.
  • [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety filters were found. The documentation is strictly technical and instructional.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — frappe-patterns