nestjs-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of educational content and reference documentation for the NestJS framework. It provides patterns for authentication (JWT, Passport, OAuth2), database integration (TypeORM, Prisma, Drizzle), microservices (TCP, Redis, NATS, Kafka), and request lifecycle management (Middleware, Guards, Interceptors, Pipes).
  • [SAFE]: Hardcoded credentials are not present; the skill correctly demonstrates the use of placeholders (e.g., YOUR_API_KEY_HERE) or environment variable retrieval via ConfigService (e.g., config.get('JWT_SECRET')).
  • [SAFE]: External dependencies referenced in the documentation (via npm install) are standard, well-known libraries within the Node.js and NestJS ecosystem, such as @nestjs/passport, class-validator, typeorm, and prisma.
  • [SAFE]: The documentation actively promotes security best practices, such as cautioning against using the TypeORM synchronize option in production and recommending the use of the whitelist property in ValidationPipe to prevent mass assignment vulnerabilities.
  • [SAFE]: No obfuscation, prompt injection, or malicious persistence mechanisms were detected in any of the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:00 PM
Security Audit — agent-trust-hub — nestjs-best-practices