tanstack-start-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation resource for TanStack Start, providing secure code patterns and architectural guidance.
- [SAFE]: Security-focused rules (sec-validate-inputs, sec-auth-middleware) correctly advocate for the use of schema validation (Zod) and robust authentication mechanisms to protect against common web vulnerabilities.
- [SAFE]: Authentication examples (auth-session-management) emphasize best practices such as HTTP-only cookies, secure flags in production, and proper SameSite attributes for CSRF protection.
- [SAFE]: Environment variable handling (env-functions) correctly distinguishes between server-side secrets and client-side public configuration, advising against the accidental exposure of sensitive keys.
Audit Metadata