best-practices
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides informational guidelines and documentation to help developers secure their web applications and improve code quality.
- [DATA_EXPOSURE_AND_EXFILTRATION]: Includes illustrative examples for implementing secure cookies and Content Security Policy headers, utilizing non-sensitive placeholders such as 'nonce-abc123' and 'session=abc123'.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: Recommends the use of trusted libraries like DOMPurify and well-known services like Cloudflare for secure polyfill hosting, while explicitly warning against historically compromised services like polyfill.io.
- [INDIRECT_PROMPT_INJECTION]: While the skill is intended to process and audit user-provided code, it promotes strong defense-in-depth measures such as input sanitization and Trusted Types to mitigate injection vulnerabilities in the target application.
Audit Metadata