clickhouse-js-node-coding
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill explicitly mandates the use of parameterized queries (
{name: Type}syntax) and requires the agent to warn users about SQL injection risks when using string interpolation. This is a critical security best practice. - [SAFE]: Configuration instructions consistently recommend using environment variables (
process.env) for sensitive data like URLs and passwords, rather than hardcoding them or constructing connection strings dynamically in code. - [SAFE]: All external references and dependencies are standard, official, or well-known community packages within the Node.js and ClickHouse ecosystems (e.g.,
@clickhouse/client,json-bigint,zod). - [SAFE]: The skill provides defensive programming advice, such as using schema validation libraries (
zod,io-ts) when handling untrusted data from external sources.
Audit Metadata