ptlam-agent-os-code-style-typescript-nestjs

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of documentation and architectural guidelines for an AI agent to follow when writing NestJS code. It promotes security best practices including:
  • Centralized validation at boundaries using Zod or similar libraries to prevent malformed data injection.
  • Secure logging practices such as using allowlist-based redaction to prevent secret exposure and avoiding the logging of personal data.
  • Proper environment variable handling by restricting process.env access to a dedicated configuration module.
  • Hardened HTTP adapter configurations (CORS, CSRF, security headers) to protect the application at the transport layer.
  • Dependency governance through Architecture Decision Records (ADRs) for any new third-party additions.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard development tools such as pnpm, tsc, biome, and vitest. These are standard tools for the TypeScript/NestJS ecosystem and are used here for linting, type-checking, and testing within the project's own repository scope.
  • [EXTERNAL_DOWNLOADS]: The skill references standard package installation via pnpm install and uses the catalog: feature in pnpm-workspace.yaml to manage dependencies. These are legitimate operations for managing a JavaScript/TypeScript project and do not target untrusted or suspicious remote sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:27 AM
Security Audit — agent-trust-hub — ptlam-agent-os-code-style-typescript-nestjs