nestjs-attack-probe

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured framework for auditing NestJS applications. It targets specific, documented security weaknesses like ValidationPipe gaps, missing @UseGuards, and default Swagger exposure.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform network-based probing (HTTP GET/POST and WebSocket connections) against the application under test. These actions are limited to the user's infrastructure and are essential for the skill's stated purpose of penetration testing.
  • [PROMPT_INJECTION]: The instructions do not contain adversarial patterns, jailbreak attempts, or instructions to bypass safety filters. The language is professional and focused on a technical security procedure.
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized data exfiltration. The skill facilitates local discovery of the application's base URL (via main.ts or environment variables) and reports findings directly to the user.
  • [EXTERNAL_DOWNLOADS]: The skill references official NestJS documentation (docs.nestjs.com) for remediation guidance, which are well-known and trusted technology resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 12:44 PM
Security Audit — agent-trust-hub — nestjs-attack-probe