secure-code-guardian
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a security reference guide, teaching the agent how to implement standard protections such as password hashing with bcrypt, parameterized SQL queries, and input validation with Zod.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known, industry-standard Node.js libraries for security purposes, including helmet, express-rate-limit, jsonwebtoken, and dompurify. These are used in an instructional context for enhancing application security.
- [COMMAND_EXECUTION]: The skill explicitly instructs against the use of unsafe command execution (exec) and demonstrates the secure alternative (execFile) to prevent command injection vulnerabilities.
- [DATA_EXPOSURE]: The skill promotes secure secrets management by instructing the use of environment variables instead of hardcoded credentials.
Audit Metadata