security-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely educational and documentation-based, designed to help developers implement security best practices.
- [CREDENTIALS_UNSAFE]: The skill contains examples of hardcoded secrets (e.g., 'sk-proj-xxxxx', 'password123'), but these are explicitly labeled as patterns that must not be used ('NEVER Do This') and do not represent actual leaked credentials.
- [COMMAND_EXECUTION]: The skill references standard development commands such as 'npm audit' and 'npm update' within its documentation, providing correct guidance for maintaining dependency security.
- [DATA_EXPOSURE]: The skill correctly identifies and warns against common data exposure patterns, such as logging sensitive information or revealing detailed stack traces in error messages.
Audit Metadata