node-express-prisma

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured templates and best practices for Node.js development, including DTO-based validation and centralized error handling. These patterns help prevent common web vulnerabilities like mass assignment and unhandled exceptions.- [SAFE]: Credentials and secrets (e.g., JWT_SECRET, DATABASE_URL) are managed via environment variables rather than being hardcoded in the source code, adhering to standard security practices for configuration management.- [SAFE]: Password security is addressed using bcrypt for hashing before storage, and sensitive fields like passwords are explicitly excluded from response DTOs using class-transformer to prevent data leakage.- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing untrusted user input via HTTP request bodies, queries, and parameters, creating a surface for potential injection if not handled correctly.
  • Ingestion points: Data enters the system through req.body, req.query, and req.params in various controllers defined in SKILL.md (e.g., UserController).
  • Boundary markers: The skill recommends validation using class-validator DTOs and a custom validateDto middleware to filter and validate input before it reaches business logic.
  • Capability inventory: The skill facilitates database interactions via Prisma ORM and HTTP response delivery via Express.
  • Sanitization: Input is sanitized and validated through plainToInstance and validate() calls within the validateDto middleware.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — node-express-prisma