tanstack-start-best-practices
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a well-structured set of development guidelines that promote secure coding practices.
- [PROMPT_INJECTION]: No malicious instructions or bypass attempts were found in the skill metadata or body.
- [CREDENTIALS_UNSAFE]: The skill demonstrates safe credential handling by recommending the use of environment variables and providing configuration for secure, encrypted session cookies. No hardcoded secrets are present.
- [DATA_EXFILTRATION]: No evidence of data exfiltration or suspicious network activity was found. Network-related code examples are appropriate for the application context (e.g., Stripe webhooks).
- [COMMAND_EXECUTION]: All included command-line examples are standard development and deployment tasks (e.g., build commands, Docker setup) and pose no security risk.
- [REMOTE_CODE_EXECUTION]: No patterns for downloading or executing untrusted remote scripts were identified. The deployment configurations target well-known cloud providers.
Audit Metadata