security-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively provides instructional content and code templates demonstrating security best practices.
- [DATA_EXPOSURE]: While the skill contains a snippet labeled as a hardcoded secret (
sk-proj-xxxxx), it is explicitly marked as a negative example (\u274c NEVER Do This) and uses a clearly redacted placeholder, posing no risk. - [COMMAND_EXECUTION]: The skill mentions common developer commands such as
npm auditandnpm updatewithin a documentation context. It does not contain any executable logic or dynamic context injection patterns that would run commands automatically.
Audit Metadata