skills/fam-tung-lam/ptlam-agent-plugin/ptlam-agent-os-code-style-typescript-nestjs/Gen Agent Trust Hub
ptlam-agent-os-code-style-typescript-nestjs
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of documentation and architectural guidelines for an AI agent to follow when writing NestJS code. It promotes security best practices including:
- Centralized validation at boundaries using Zod or similar libraries to prevent malformed data injection.
- Secure logging practices such as using allowlist-based redaction to prevent secret exposure and avoiding the logging of personal data.
- Proper environment variable handling by restricting
process.envaccess to a dedicated configuration module. - Hardened HTTP adapter configurations (CORS, CSRF, security headers) to protect the application at the transport layer.
- Dependency governance through Architecture Decision Records (ADRs) for any new third-party additions.
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard development tools such as
pnpm,tsc,biome, andvitest. These are standard tools for the TypeScript/NestJS ecosystem and are used here for linting, type-checking, and testing within the project's own repository scope. - [EXTERNAL_DOWNLOADS]: The skill references standard package installation via
pnpm installand uses thecatalog:feature inpnpm-workspace.yamlto manage dependencies. These are legitimate operations for managing a JavaScript/TypeScript project and do not target untrusted or suspicious remote sources.
Audit Metadata