backend-dev-guidelines
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting and processing untrusted data from HTTP requests (body, query params, route params). It addresses this risk surface by mandating the use of Zod for strict schema validation and input sanitization before data reaches the service or database layers.
- [EXTERNAL_DOWNLOADS]: The documentation references several well-known and industry-standard libraries and services, including Express, Prisma, Zod, and Sentry. These are recognized as well-known technology services used for legitimate development purposes.
- [DATA_EXFILTRATION]: The skill mandates the use of Sentry for error tracking and performance monitoring. While this involves sending data to an external service, the provided
instrument.tstemplate includes explicit security measures to scrub sensitive headers likeAuthorizationandCookie, and to mask PII such as email addresses before transmission. - [CREDENTIALS_SAFE]: The guidelines promote a 'unifiedConfig' pattern that discourages hardcoding secrets and specifically instructs developers not to commit sensitive files like
config.inior.envto version control.
Audit Metadata