nodejs-best-practices

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional documentation and architectural guidelines for Node.js development. It does not contain executable code, obfuscated strings, or suspicious commands.
  • [EXTERNAL_DOWNLOADS]: The skill mentions various standard Node.js frameworks and libraries (Hono, Fastify, Express, Zod, etc.) as architectural recommendations. These are well-known, legitimate packages within the JavaScript ecosystem.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The instructions focus on guiding the agent's reasoning during development tasks.
  • [DATA_EXFILTRATION]: No network operations, sensitive file access, or credential harvesting patterns were found. The skill explicitly advises against hardcoding secrets and suggests using environment variables.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess spawning, or direct execution of system tools. It defines a set of allowed-tools (Read, Write, Edit, Glob, Grep) appropriate for its purpose as a development assistant.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 06:10 PM
Security Audit — agent-trust-hub — nodejs-best-practices