elysia
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as an architectural guide for Elysia development, recommending secure practices such as runtime validation with TypeBox, environment-variable-based secret management, and preventing sensitive data leakage in production error responses.
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for handling external API input, creating a potential attack surface common to all web frameworks. It mitigates this by mandating strict schema validation. Ingestion points: API handlers for body, query, and path parameters in index.ts files. Boundary markers: The instructions strongly enforce the use of TypeBox (t.Object, t.String, etc.) for all input and output schemas. Capability inventory: Business logic is encapsulated in service.ts modules called by the controllers. Sanitization: Automatic runtime validation and type-checking are integrated into the recommended scaffolding.
Audit Metadata