node-express-prisma
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides structured templates and best practices for Node.js development, including DTO-based validation and centralized error handling. These patterns help prevent common web vulnerabilities like mass assignment and unhandled exceptions.- [SAFE]: Credentials and secrets (e.g.,
JWT_SECRET,DATABASE_URL) are managed via environment variables rather than being hardcoded in the source code, adhering to standard security practices for configuration management.- [SAFE]: Password security is addressed usingbcryptfor hashing before storage, and sensitive fields like passwords are explicitly excluded from response DTOs usingclass-transformerto prevent data leakage.- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing untrusted user input via HTTP request bodies, queries, and parameters, creating a surface for potential injection if not handled correctly. - Ingestion points: Data enters the system through
req.body,req.query, andreq.paramsin various controllers defined inSKILL.md(e.g.,UserController). - Boundary markers: The skill recommends validation using
class-validatorDTOs and a customvalidateDtomiddleware to filter and validate input before it reaches business logic. - Capability inventory: The skill facilitates database interactions via Prisma ORM and HTTP response delivery via Express.
- Sanitization: Input is sanitized and validated through
plainToInstanceandvalidate()calls within thevalidateDtomiddleware.
Audit Metadata