nodejs-best-practices
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional documentation and architectural guidelines for Node.js development. It does not contain executable code, obfuscated strings, or suspicious commands.
- [EXTERNAL_DOWNLOADS]: The skill mentions various standard Node.js frameworks and libraries (Hono, Fastify, Express, Zod, etc.) as architectural recommendations. These are well-known, legitimate packages within the JavaScript ecosystem.
- [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The instructions focus on guiding the agent's reasoning during development tasks.
- [DATA_EXFILTRATION]: No network operations, sensitive file access, or credential harvesting patterns were found. The skill explicitly advises against hardcoding secrets and suggests using environment variables.
- [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess spawning, or direct execution of system tools. It defines a set of allowed-tools (Read, Write, Edit, Glob, Grep) appropriate for its purpose as a development assistant.
Audit Metadata