clickhouse-js-node-coding

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill explicitly mandates the use of parameterized queries ({name: Type} syntax) and requires the agent to warn users about SQL injection risks when using string interpolation. This is a critical security best practice.
  • [SAFE]: Configuration instructions consistently recommend using environment variables (process.env) for sensitive data like URLs and passwords, rather than hardcoding them or constructing connection strings dynamically in code.
  • [SAFE]: All external references and dependencies are standard, official, or well-known community packages within the Node.js and ClickHouse ecosystems (e.g., @clickhouse/client, json-bigint, zod).
  • [SAFE]: The skill provides defensive programming advice, such as using schema validation libraries (zod, io-ts) when handling untrusted data from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:01 PM
Security Audit — agent-trust-hub — clickhouse-js-node-coding