backend-dev-guidelines

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting and processing untrusted data from HTTP requests (body, query params, route params). It addresses this risk surface by mandating the use of Zod for strict schema validation and input sanitization before data reaches the service or database layers.
  • [EXTERNAL_DOWNLOADS]: The documentation references several well-known and industry-standard libraries and services, including Express, Prisma, Zod, and Sentry. These are recognized as well-known technology services used for legitimate development purposes.
  • [DATA_EXFILTRATION]: The skill mandates the use of Sentry for error tracking and performance monitoring. While this involves sending data to an external service, the provided instrument.ts template includes explicit security measures to scrub sensitive headers like Authorization and Cookie, and to mask PII such as email addresses before transmission.
  • [CREDENTIALS_SAFE]: The guidelines promote a 'unifiedConfig' pattern that discourages hardcoding secrets and specifically instructs developers not to commit sensitive files like config.ini or .env to version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — backend-dev-guidelines