hono-backend
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive instructions for building Hono applications using official patterns and security-focused middleware such as
secureHeaders,cors, andbodyLimit.- [INDIRECT_PROMPT_INJECTION]: The skill manages untrusted request data, which is an inherent attack surface for indirect prompt injection. - Ingestion points: Data is ingested via
c.req.json(),c.req.query(),c.req.param(), andc.req.parseBody()inSKILL.md. - Boundary markers: The instructions explicitly recommend using schema-based validation middleware (
zValidator,sValidator) to delimit and verify external input. - Capability inventory: Capabilities include standard HTTP routing, middleware execution, and CLI-based request testing (
hono request). - Sanitization: Emphasizes using libraries like Zod and Valibot for runtime input validation and sanitization.- [EXTERNAL_DOWNLOADS]: The skill mentions official project creation commands like
bun create hono@latestandnpm create hono@latest. These are standard tools for the Hono ecosystem and are considered safe.- [CREDENTIALS_UNSAFE]: An illustrative code snippet inSKILL.mdusespassword: 'secret'as a placeholder for thebasicAuthmiddleware. This is for educational purposes and is not a hardcoded secret intended for production use.
Audit Metadata