hono-backend

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive instructions for building Hono applications using official patterns and security-focused middleware such as secureHeaders, cors, and bodyLimit.- [INDIRECT_PROMPT_INJECTION]: The skill manages untrusted request data, which is an inherent attack surface for indirect prompt injection.
  • Ingestion points: Data is ingested via c.req.json(), c.req.query(), c.req.param(), and c.req.parseBody() in SKILL.md.
  • Boundary markers: The instructions explicitly recommend using schema-based validation middleware (zValidator, sValidator) to delimit and verify external input.
  • Capability inventory: Capabilities include standard HTTP routing, middleware execution, and CLI-based request testing (hono request).
  • Sanitization: Emphasizes using libraries like Zod and Valibot for runtime input validation and sanitization.- [EXTERNAL_DOWNLOADS]: The skill mentions official project creation commands like bun create hono@latest and npm create hono@latest. These are standard tools for the Hono ecosystem and are considered safe.- [CREDENTIALS_UNSAFE]: An illustrative code snippet in SKILL.md uses password: 'secret' as a placeholder for the basicAuth middleware. This is for educational purposes and is not a hardcoded secret intended for production use.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:11 AM
Security Audit — agent-trust-hub — hono-backend