fullstack-guardian
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements best practices for security including mandatory parameterized queries to prevent SQL injection, and server-side validation using established libraries like Zod and Pydantic.
- [SAFE]: It provides detailed templates for Authentication (JWT/SSO) and Authorization (RBAC/Resource ownership) ensuring that access control is treated as a core requirement for every feature.
- [SAFE]: The code snippets across all reference files demonstrate secure coding patterns, such as implementing rate limiting for authentication endpoints, using secure HTTP headers, and ensuring sensitive data is excluded from API responses through explicit schemas.
- [SAFE]: The guidance on DevOps and deployment includes multi-stage Docker builds to reduce image attack surface and CI/CD pipelines with automated security testing.
- [SAFE]: All external references target well-known open-source libraries (e.g., Zod, NestJS, FastAPI) or standard platform features without downloading executable code from untrusted remote sources.
Audit Metadata